#VU84865 Stored cross-site scripting in FortiNAC and FortiNAC-F - CVE-2023-22637
Published: December 29, 2023
FortiNAC
FortiNAC-F
Fortinet, Inc
Description
The disclosed vulnerability allows a remote user to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via crafted licenses in FortiNAC License Management. A remote user can upload a specially crafted license file and execute arbitrary HTML and script code in user's browser in context of vulnerable website.