cbcvebase.
CVE-2025-22855
published 2025-04-08

CVE-2025-22855: An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow…

medium4.8CVSS 3.1
AVNACLPRHUIRSCCLILAN
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetforticlient
fortinetforticlientems
fortinetforticlientems7.2.1 – 7.2.10
fortinetforticlientems>= 7.4.0 < 7.4.37.4.3
fortinetforticlientems7.4.0 – 7.4.1
fortinetfortinet