Description
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.
No analysis available yet.
Remediation
Vendor Solution
Please upgrade to FortiNAC version 9.4.4 or above Please upgrade to FortiNAC version 7.2.3 or above
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30031 | An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs. |
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-23-063 |
|
History
No history.
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T11:39:06.654Z
Reserved: 2023-02-20T15:09:20.635Z
Link: CVE-2023-26206
Updated: 2024-08-02T11:39:06.654Z
Status : Modified
Published: 2024-02-15T14:15:44.597
Modified: 2024-11-21T07:50:54.880
Link: CVE-2023-26206
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD