Impact
An improper neutralization of script‑related HTML tags in Fortinet FortiSIEM introduces a basic cross‑site scripting flaw, classified as CWE‑80. The vulnerability allows an attacker to inject scripts that are rendered in a victim’s browser, potentially leading to the execution of arbitrary code or commands within the context of the web application. The provided description does not specify any downstream consequences beyond this code execution capability.
Affected Systems
Fortinet FortiSIEM is affected across multiple product lines. The vulnerability exists in all releases from version 6.2.0 through 7.4.0, including the 7.3.0‑7.3.4 and 7.2.0‑7.2.6 ranges, all 7.1 releases, all 7.0 releases, and all 6.7, 6.6, 6.5, and 6.4 releases. Versions 7.4.1, 7.3.5, 7.2.7, and any later releases (e.g., 7.5.0 and above) contain the fix and are not affected.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score of < 1 % suggests low current exploitation pressure. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely achievable via a web interface that accepts user‑supplied content such as form inputs, URL parameters, or other data fields, where the injected script is subsequently rendered. The attack vector is inferred to be remote, web‑based, and requires the ability to deliver crafted payloads to target pages.
OpenCVE Enrichment