Cross-Site Scripting Vulnerability in Fortinet FortiSIEM
CVE-2026-25972
4.1MEDIUM
What is CVE-2026-25972?
An improper neutralization of input during web page generation vulnerability exists in Fortinet's FortiSIEM versions 7.4.0 and 7.3.0 through 7.3.4. This flaw allows remote unauthenticated attackers to inject arbitrary data through URL parameters. Exploiting this vulnerability can facilitate social engineering attacks, potentially leading to the compromise of user interactions and sensitive information.
Affected Version(s)
FortiSIEM 7.4.0
FortiSIEM 7.3.0 <= 7.3.4