Reflected XSS (cross site scripting) in incident page

Summary

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP requests.

Version Affected Solution
FortiSIEM 7.3 Not affected Not Applicable
FortiSIEM 7.2 Not affected Not Applicable
FortiSIEM 7.1 7.1 all versions Migrate to a fixed release
FortiSIEM 7.0 7.0 all versions Migrate to a fixed release
FortiSIEM 6.7 6.7 all versions Migrate to a fixed release
FortiSIEM 6.6 Not affected Not Applicable
FortiSIEM 6.5 Not affected Not Applicable
FortiSIEM 6.4 Not affected Not Applicable
FortiSIEM 6.3 Not affected Not Applicable
FortiSIEM 6.2 Not affected Not Applicable
FortiSIEM 6.1 Not affected Not Applicable
FortiSIEM 5.4 Not affected Not Applicable

Acknowledgement

Fortinet is pleased to thank Charlie Lindholm from Integrity360, and Christian Arlt for reporting this vulnerability under responsible disclosure.

Timeline

2025-02-11: Initial publication