Description


An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

Related CPE's


a

fortinet

forticlientems

2

Weaknesses



CWE-79

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

2.7 · Low

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-04-08T12:15:32.690Z

11 months ago

Last modified

2025-07-23T14:03:19.720Z

7 months ago