Cross-Site Scripting Vulnerability in Fortinet FortiClient
CVE-2025-22855
2.6LOW
What is CVE-2025-22855?
An input validation flaw within the Fortinet FortiClient allows for the improper handling of input during web page generation, potentially enabling an attacker to embed malicious JavaScript code. When exploited, this vulnerability can allow EMS administrators to inadvertently send messages containing harmful scripts, which could compromise the security of users accessing affected web pages.
Affected Version(s)
FortiClientEMS 7.4.0 <= 7.4.1
FortiClientEMS 7.2.1 <= 7.2.8