We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-22637



Assignerfortinet
Reserved2023-01-05
Published2023-05-03
Updated2024-10-23

Description

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger remote code execution via crafted licenses.



MEDIUM: 5.9CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R

Product status

Default status
unaffected

9.4.0
affected

9.2.0
affected

9.1.0
affected

8.8.0
affected

8.7.0
affected

References

https://fortiguard.com/psirt/FG-IR-23-013

cve.org CVE-2023-22637

nvd.nist.gov CVE-2023-22637

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.