# Exploit Title: FortiSiem 7.1.3 Stored XSS
# Google Dork: N/A
# Date: 06.09.2024
# Exploit Author: Ersin Sarisoy
# Vendor Homepage: https://www.fortinet.com/
# Software Link: https://www.fortinet.com/products/siem/fortisiem
# Version: 7.1.3 and below
# Tested on: Kali Linux & Windows
# CVE : N/A
After a classic introduction to FortiSiem
Click Admin>Device Support>Parsers later Test parser Edit>Validate>Test
you should see this:
{{constructor.constructor….
and you should convert that value to:
{{constructor.constructor….('alert(1)')()}}
And click test.