Cross-Site Scripting in Domain parameter

MonitorCVSS 5.3FG-IR-26-149Jul 14, 2026
Fortinet
IT in OT - Fortinet products are commonly deployed at IT/OT network boundaries
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityLow
User InteractionRequired
Summary

Cross-Site Scripting vulnerability in FortiSIEM web interface Domain parameter. An authenticated high-privilege user can inject malicious JavaScript that executes in the context of other users' browser sessions, potentially allowing theft of session credentials or unauthorized actions on the SIEM platform.

What this means
What could happen
An authenticated user with high privileges could inject malicious scripts into the FortiSIEM web interface that execute in the browsers of other users who view the affected pages, allowing them to steal session credentials or redirect operations staff to malicious sites.
Who's at risk
SIEM administrators and security operations center (SOC) staff who use Fortinet FortiSIEM for log aggregation and threat monitoring. The vulnerability affects all users who may view configuration pages that include the Domain parameter, such as authentication or data source configuration screens.
How it could be exploited
An attacker with administrative or high-privilege credentials injects JavaScript code into the Domain parameter of a FortiSIEM configuration page. When other users access that page through the web interface, the script executes in their browser, potentially stealing authentication tokens or performing unauthorized actions on their behalf.
Prerequisites
  • High-privilege FortiSIEM user account (administrator or equivalent role)
  • Network access to FortiSIEM web interface (port 443 or configured HTTPS port)
  • Victim user must visit the page containing the injected Domain parameter
Requires high privilege credentialsRequires user interaction (victim must view injected content)Low attack complexityModerate CVSS score
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (3)
3 with fix
ProductAffected VersionsFix Status
FortiSIEM7.4.07.4.1+
FortiSIEM7.3.0 - 7.3.47.3.5+
FortiSIEM7.2.0 - 7.2.6 and 6 more7.2.7+
Remediation & Mitigation
0/5
Do now
0/1
FortiSIEM
HARDENINGEnable HTTP-only and Secure flags on FortiSIEM session cookies to prevent script-based credential theft
Schedule — requires maintenance window
0/3

Patching may require device reboot — plan for process interruption

FortiSIEM
HOTFIXUpdate FortiSIEM 7.4.x to version 7.4.1 or later
HOTFIXUpdate FortiSIEM 7.3.x to version 7.3.5 or later
HOTFIXUpdate FortiSIEM 7.2.x or earlier supported versions to 7.2.7 or later
Long-term hardening
0/1
FortiSIEM
HARDENINGRestrict administrative access to FortiSIEM to trusted users and workstations only
API: /api/v1/advisories/247c8609-72ef-4c92-bb39-da59f8dd4cd2

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Cross-Site Scripting in Domain parameter | CVSS 5.3 - OTPulse