Stored XSS in playbook block

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

Version Affected Solution
FortiSOAR on-premise 7.6 Not affected Not Applicable
FortiSOAR on-premise 7.5 Not affected Not Applicable
FortiSOAR on-premise 7.4 Not affected Not Applicable
FortiSOAR on-premise 7.3 7.3 all versions Migrate to a fixed release
FortiSOAR on-premise 7.2 7.2.1 through 7.2.2 Migrate to a fixed release
FortiSOAR on-premise 7.0 Not affected Not Applicable

Acknowledgement

Internally discovered and reported by Xin Zhao of Fortinet InfoSec team.

Timeline

2025-01-14: Initial publication