CVE-2024-27780

Severity
5.4MEDIUM
EPSS
0.2%
top 56.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11

Description

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:NExploitability: 0.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5fortinet/fortisiem7.1.07.1.7+2
NVDfortinet/fortisiem6.7.06.7.9+2

🔴Vulnerability Details

2
GHSA
GHSA-r5g9-gp44-29h8: Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 72025-02-11
CVEList
CVE-2024-27780: Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 72025-02-11

📋Vendor Advisories

1
Fortinet
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] i...2025-02-11
CVE-2024-27780 (MEDIUM CVSS 5.4) | Multiple Improper Neutralization of | cvebase.io