XSS vulnerability in communications triggered in playbooks

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR may allow a remote authenticated attacker to perform a stored cross site scripting (XSS) attack via the Communications module.

Version Affected Solution
FortiSOAR on-premise 7.6 Not affected Not Applicable
FortiSOAR on-premise 7.5 Not affected Not Applicable
FortiSOAR on-premise 7.4 7.4.0 Upgrade to 7.4.1 or above
FortiSOAR on-premise 7.3 7.3.0 through 7.3.2 Upgrade to 7.3.3 or above
FortiSOAR on-premise 7.2 7.2 all versions Migrate to a fixed release
FortiSOAR on-premise 7.0 7.0 all versions Migrate to a fixed release
FortiSOAR on-premise 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Fortinet is pleased to thank Swati Jinde from Fortinet's QA team.

Timeline

2024-08-13: Initial publication