XSS in service requests

Summary

An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests

Version Affected Solution
FortiSOAR on-premise 7.6 7.6.0 through 7.6.1 Upgrade to 7.6.2 or above
FortiSOAR on-premise 7.5 7.5.0 through 7.5.1 Upgrade to 7.5.2 or above
FortiSOAR on-premise 7.4 7.4 all versions Migrate to a fixed release
FortiSOAR on-premise 7.3 7.3 all versions Migrate to a fixed release
FortiSOAR on-premise 7.2 7.2 all versions Migrate to a fixed release
FortiSOAR on-premise 7.0 7.0 all versions Migrate to a fixed release
FortiSOAR on-premise 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Lien-Bee Huang of Fortinet Product Security team. Fortinet is also pleased to thank GAHEE LEE (이가희) from Shinhan for reporting this vulnerability under responsible disclosure.

Timeline

2025-08-12: Initial publication