CVE-2023-26211: XSS
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26211?
CVE-2023-26211 has been rated as a high severity vulnerability due to its potential for exploitation in web applications.
How do I fix CVE-2023-26211?
To mitigate CVE-2023-26211, it is recommended to update Fortinet FortiSOAR to version 7.3.3 or later.
What types of attacks are possible with CVE-2023-26211?
CVE-2023-26211 allows an attacker to execute arbitrary web scripts or HTML by exploiting cross-site scripting vulnerabilities.
Who is affected by CVE-2023-26211?
CVE-2023-26211 affects users of Fortinet FortiSOAR versions 7.3.0 to 7.3.2 and version 7.4.0.
What modules are implicated in CVE-2023-26211?
The Communications module of Fortinet FortiSOAR is specifically vulnerable in CVE-2023-26211.