GHSA-vpwg-c4h3-2hjj
GitHub Security Advisory
⚠ Unreviewed
LOW
Has CVE
Advisory Details
An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5 and below may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: August 11, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.