> XSS in service requests
[DATE: 12/08/2025 07:00]
[LANGUAGE: EN]
An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests Revised on 2025-08-12 00:00:00