CVE-2023-26211

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
13/08/2024
Last modified:
22/08/2024

Description

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:fortisoar:*:*:*:*:*:*:*:* 6.4.0 (including) 7.3.3 (excluding)
cpe:2.3:a:fortinet:fortisoar:7.4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools