[FortiSiem][XSS] XSS in the description and title field of a new schedule

Summary

An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSiem may allow a remote authenticated attacker to perform a Stored Cross Site Scripting attack (XSS) by injecting malicious JavaScript code into the description field of a Device Maintenance schedule.

Affected Products

FortiSIEM version 5.2.5 and below.

Solutions

Please upgrade to FortiSIEM version 5.2.6 and above.

Acknowledgement

Fortinet is very pleased to thank Luca Sangalli (luca91.sanga@gmail.com ; https://it.linkedin.com/in/luca-sangalli-0a6462105) for bringing this issue to our attention under responsible disclosure and for helping us make our products more secure.