Vulnerabilities > Fortinet > Fortisoar

DATE CVE VULNERABILITY TITLE RISK
2025-01-22 CVE-2022-23439 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Fortinet products
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before version 7.0.4, FortiRecorder version 6.4.0 through 6.4.2 and before 6.0.10, FortiAuthenticator version 6.4.0 through 6.4.1 and before 6.3.3, FortiNDR version 7.2.0 before 7.1.0, FortiWLC before version 8.6.4, FortiPortal before version 6.0.9, FortiOS version 7.2.0 and before 7.0.5, FortiADC version 7.0.0 through 7.0.1 and before 6.2.3 , FortiDDoS before version 5.5.1, FortiDDoS-F before version 6.3.3, FortiTester before version 7.2.1, FortiSOAR before version 7.2.2 and FortiSwitch before version 6.3.3 allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
network
low complexity
fortinet CWE-610
6.1
2025-01-14 CVE-2024-36510 Information Exposure Through Discrepancy vulnerability in Fortinet Forticlientems and Fortisoar
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing login request responses.
network
low complexity
fortinet CWE-203
5.3
2025-01-14 CVE-2024-48893 Cross-site Scripting vulnerability in Fortinet Fortisoar
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.
network
low complexity
fortinet CWE-79
5.4
2024-09-11 CVE-2024-45327 Improper Restriction of Excessive Authentication Attempts vulnerability in Fortinet Fortisoar
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an authenticated attacker to perform a brute force attack on users and administrators password via crafted HTTP requests.
network
high complexity
fortinet CWE-307
7.5
2024-08-13 CVE-2023-26211 Cross-site Scripting vulnerability in Fortinet Fortisoar
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
network
low complexity
fortinet CWE-79
critical
9.0
2024-06-11 CVE-2023-23775 Unspecified vulnerability in Fortinet Fortisoar
Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.0.3 may allow an authenticated attacker to execute unauthorized code or commands via specifically crafted strings parameters.
network
low complexity
fortinet
8.8
2024-06-03 CVE-2024-31493 Unspecified vulnerability in Fortinet Fortisoar
An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.
network
low complexity
fortinet
6.5
2023-04-11 CVE-2023-27995 Unspecified vulnerability in Fortinet Fortisoar 7.3.0/7.3.1
A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticated, remote attacker to execute arbitrary code via a crafted payload.
network
low complexity
fortinet
8.8
2023-03-07 CVE-2023-25605 Unspecified vulnerability in Fortinet Fortisoar 7.3.0/7.3.1
A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perform unauthorized actions via crafted HTTP requests.
network
low complexity
fortinet
7.2
2022-12-06 CVE-2022-38379 Cross-site Scripting vulnerability in Fortinet Fortisoar
Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker to inject HTML tags via input fields of various components within FortiSOAR.
network
low complexity
fortinet CWE-79
5.4