Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.
2023-02-16T19:15:12.860
2024-11-21T07:16:21.097
Modified
CVSSv3.1: 6.1 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | fortinac | ≤ 8.5.4 | Yes |
Application | fortinet | fortinac | < 9.4.2 | Yes |
Application | fortinet | fortinac | 8.3.7 | Yes |