A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all versions, FortiADC 7.2 all versions may allow attacker to execute unauthorized code or commands via crafted URL.
References
| Link | Resource |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-25-736 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2025, 14:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Fortinet
Fortinet fortiadc |
|
| References | () https://fortiguard.fortinet.com/psirt/FG-IR-25-736 - Vendor Advisory | |
| CPE | cpe:2.3:a:fortinet:fortiadc:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:fortinet:fortiadc:*:*:*:*:*:*:*:* |
19 Nov 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-19 10:15
Updated : 2025-11-20 14:38
NVD link : CVE-2025-58412
Mitre link : CVE-2025-58412
CVE.ORG link : CVE-2025-58412
JSON object : View
Products Affected
fortinet
- fortiadc
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
