CVE-2024-27780: XSS
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27780?
The vulnerability CVE-2024-27780 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2024-27780?
To fix CVE-2024-27780, it is recommended to upgrade FortiSIEM to a version that addresses the vulnerability.
What versions of FortiSIEM are affected by CVE-2024-27780?
FortiSIEM versions 6.7, 7.0, and 7.1 are all affected by CVE-2024-27780.
Can an unauthenticated user exploit CVE-2024-27780?
No, CVE-2024-27780 can only be exploited by an authenticated attacker.
What type of attack can CVE-2024-27780 lead to?
CVE-2024-27780 can lead to a cross-site scripting (XSS) attack, allowing attackers to execute scripts in the context of a user's browser.