imPC@ndo IT

Tracker / CVE-2025-22855

CVE-2025-22855

Low 2.7

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.

Affected products and versions

fortinet forticlientems · 7.2.1 → 7.2.10
fortinet forticlientems · 7.4.0 → 7.4.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References