CVE-2024-31488
An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 t
Description
An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
Weakness: CWE-79
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiNAC | Identity / IAM / MFA | cna-assigner |
Vendor-reported products (7)
- Fortinet · FortiNAC
- fortinet · fortinac
- fortinet · fortinac
- fortinet · fortinac
- fortinet · fortinac
- fortinet · fortinac
- fortinet · fortinac
Credit
Internally discovered and reported by Heidi White and Brian Bull of Fortinet QA team.
Vendor remediation
Please upgrade to FortiNAC version 9.4.5 or above Please upgrade to FortiNAC version 7.4.0 or above Please upgrade to FortiNAC version 7.2.4 or above