FORTINET Security Advisory

Published Date: Not specified

Advisory Summary

🔔 🛑 Open Redirect Weakness in FortiSIEM (CWE-601)
FortiSIEM is reported to have an open redirect vulnerability (CVSSv3 2.8) where an authenticated attacker can craft HTTP requests to redirect users to any untrusted website.

🛠️ Risks / threat scenario
An attacker with valid credentials uses crafted parameters to force the application to redirect to an attacker-controlled domain—potentially capturing credentials, session tokens (via additional attacks), or prompting unsafe actions.

📌
đź”— https://fortiguard.fortinet.com/psirt/FG-IR-26-169

-601