CVE-2026-25972 | Fortinet FortiSIEM up to 7.3.4/7.4.0 URL Parameter cross site scripting (FG-IR-26-077)
A vulnerability labeled as problematic has been found in Fortinet FortiSIEM up to 7.3.4/7.4.0. This vulnerability affects unknown code of the component URL Parameter Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-25972. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.