Aller au contenu

Fiche vulnérabilité

CVE-2025-32932 : faille moyenne fortinet fortisoar (CVSS 5.4)

Description

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
12 août 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • fortinet fortisoar

Références

Rechercher une autre vulnérabilité dans la base CVE