PT-2025-41964 · Fortinet · Fortisiem

Published

2025-10-14

·

Updated

2025-10-16

·

CVE-2025-58324

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FortiSIEM versions 6.2 through 7.2.2 FortiSIEM versions 7.0 FortiSIEM versions 7.1 FortiSIEM versions 6.3 FortiSIEM versions 6.4 FortiSIEM versions 6.5 FortiSIEM versions 6.6 FortiSIEM versions 6.7
Description An improper neutralization of input during web page generation issue exists, which may allow an authenticated attacker to perform a stored cross-site scripting (XSS) attack via crafted HTTP requests. The issue is related to web page generation.
Recommendations Update FortiSIEM to a version later than 7.2.2. Update FortiSIEM to a version later than 7.1. Update FortiSIEM to a version later than 7.0. Update FortiSIEM to a version later than 6.7. Update FortiSIEM to a version later than 6.6. Update FortiSIEM to a version later than 6.5. Update FortiSIEM to a version later than 6.4. Update FortiSIEM to a version later than 6.3. Update FortiSIEM to a version later than 6.2.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05211
CVE-2025-58324

Affected Products

Fortisiem