Stored XSS in parser tester

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP requests.

Version Affected Solution
FortiSIEM 7.4 Not affected Not Applicable
FortiSIEM 7.3 Not affected Not Applicable
FortiSIEM 7.2 7.2.0 through 7.2.2 Upgrade to 7.2.3 or above
FortiSIEM 7.1 7.1 all versions Migrate to a fixed release
FortiSIEM 7.0 7.0 all versions Migrate to a fixed release
FortiSIEM 6.7 6.7 all versions Migrate to a fixed release
FortiSIEM 6.6 6.6 all versions Migrate to a fixed release
FortiSIEM 6.5 6.5 all versions Migrate to a fixed release
FortiSIEM 6.4 6.4 all versions Migrate to a fixed release
FortiSIEM 6.3 6.3 all versions Migrate to a fixed release
FortiSIEM 6.2 6.2 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Ersin SARISOY from Beyaz Net for reporting this vulnerability under responsible disclosure.

Timeline

2025-10-14: Initial publication