An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-29368 | An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests. |
Fixes
Solution
Please upgrade to FortiNAC version 9.4.5 or above Please upgrade to FortiNAC version 7.4.0 or above Please upgrade to FortiNAC version 7.2.4 or above
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://fortiguard.com/psirt/FG-IR-24-040 |
|
History
Tue, 21 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: fortinet
Published:
Updated: 2024-08-02T01:52:57.296Z
Reserved: 2024-04-04T12:52:41.585Z
Link: CVE-2024-31488
Updated: 2024-05-17T12:21:19.444Z
Status : Analyzed
Published: 2024-05-14T17:17:23.733
Modified: 2025-01-21T21:47:47.183
Link: CVE-2024-31488
No data.
OpenCVE Enrichment
No data.
EUVD