EMS can send javascript code to client through messages

Summary

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiClient may allow the EMS administrator to send messages containing javascript code.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.3 or above
FortiClientEMS 7.2 7.2.1 through 7.2.10 Migrate to a fixed release
FortiClientEMS 7.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team. Fortinet is also pleased to thank Anders Sjögren from Root Cause Security and Yaniv Nizry from Sonar for reporting this vulnerability under responsible disclosure.

Timeline

2025-04-08: Initial publication