CVE-2024-48893: XSS
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability type of CVE-2024-48893?
CVE-2024-48893 is a stored cross-site scripting (XSS) vulnerability due to improper neutralization of input in FortiSOAR.
What versions are affected by CVE-2024-48893?
CVE-2024-48893 affects FortiSOAR versions 7.3.0 through 7.3.3 and 7.2.1 through 7.2.2.
How can I mitigate the risks associated with CVE-2024-48893?
To mitigate CVE-2024-48893, upgrade FortiSOAR to a version that is not affected by the vulnerability.
Who can exploit CVE-2024-48893?
An authenticated attacker can exploit CVE-2024-48893 by creating malicious playbooks.
What impact does CVE-2024-48893 have on affected systems?
CVE-2024-48893 allows attackers to perform a stored XSS attack, leading to potential data theft or unauthorized actions.