Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Please upgrade to FortiSIEM version 7.3.0 or above Please upgrade to FortiSIEM version 7.2.0 or above
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-24973 | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests. |
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-324 |
|
Wed, 16 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet fortisiem |
|
| CPEs | cpe:2.3:a:fortinet:fortisiem:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet fortisiem |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 12 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2025-02-12T15:40:18.384Z
Reserved: 2024-02-26T14:46:31.334Z
Link: CVE-2024-27780
Updated: 2025-02-12T15:40:14.348Z
Status : Analyzed
Published: 2025-02-11T17:15:21.850
Modified: 2025-07-16T14:54:28.867
Link: CVE-2024-27780
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:07:36Z
EUVD