Stored cross-site scripting in FortiNAC-F and FortiNAC - CVE-2023-22637
Published: December 29, 2023
Vulnerability details
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via crafted licenses in FortiNAC License Management. A remote user can upload a specially crafted license file and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Affected software
FortiNAC
How to mitigate CVE-2023-22637
FortiNAC - update to 9.4.3