CVE-2024-48893: Fortinet Fortisoar

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

Affected products

  • Fortinet Fortisoar: from 7.2.1, up to and including 7.3.3

Published 2025-01-14. Last modified 2026-06-17.