CVE-2025-58324
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all
Severity
Medium 6.1
CVSS 3.1
Exploited
Not listed
EPSS
0.003
16.5th percentile
Discovered by
Not disclosed
Published
Oct 14, 2025
Assigned by fortinet
Description
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSIEM | SIEM & Log Management | cna-assigner |
Vendor-reported affected versions (1)
- Fortinet · FortiSIEM
Vendor remediation
Upgrade to FortiSIEM version 7.3.0 or above Upgrade to FortiSIEM version 7.2.3 or above