First published: Tue Jan 14 2025(Updated: )
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSOAR Imap Connector | >=7.2.1<=7.3.3 | |
Fortinet FortiSOAR Imap Connector | >=7.3.0<=7.3.3>=7.2.1<=7.2.2 |
Please upgrade to FortiSOAR version 7.4.0 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48893 is a stored cross-site scripting (XSS) vulnerability due to improper neutralization of input in FortiSOAR.
CVE-2024-48893 affects FortiSOAR versions 7.3.0 through 7.3.3 and 7.2.1 through 7.2.2.
To mitigate CVE-2024-48893, upgrade FortiSOAR to a version that is not affected by the vulnerability.
An authenticated attacker can exploit CVE-2024-48893 by creating malicious playbooks.
CVE-2024-48893 allows attackers to perform a stored XSS attack, leading to potential data theft or unauthorized actions.