Home
HIGH: 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:U/RC:CDefault status
unaffected
9.4.0
affected
9.2.0 (semver)
affected
9.1.0 (semver)
affected
8.8.0 (semver)
affected
8.7.0 (semver)
affected
8.6.0 (semver)
affected
8.5.0 (semver)
affected
8.3.7
affected
Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allows attacker to execute unauthorized code or commands via specially crafted http requests.
Problem types
Execute unauthorized code or commands
Product status
9.4.0
9.2.0 (semver)
9.1.0 (semver)
8.8.0 (semver)
8.7.0 (semver)
8.6.0 (semver)
8.5.0 (semver)
8.3.7
References
fortiguard.com/psirt/FG-IR-22-281
fortiguard.com/psirt/FG-IR-22-281