CVE-2022-38376: XSS
Published Feb 16, 2023
·Updated
Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.
Affected Software
3 affected components
Fortinet FortiNAC>=8.5.0<=8.5.4
Fortinet FortiNAC>=8.6.0<9.4.2
Fortinet FortiNAC=8.3.7
Remediation
Information
Please upgrade to FortiNAC-F version 7.2.0 or above
Please upgrade to FortiNAC version 9.4.2 or above
Event History
Feb 16, 2023
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-38376?
CVE-2022-38376 has been rated as a high severity vulnerability due to its potential to allow XSS attacks.
2
How do I fix CVE-2022-38376?
To fix CVE-2022-38376, upgrade Fortinet FortiNAC to version 9.4.1 or later.
3
What are the affected versions of Fortinet FortiNAC for CVE-2022-38376?
CVE-2022-38376 affects Fortinet FortiNAC versions from 8.3.7 up to but not including 9.4.2, and from 8.5.0 to 8.5.4.
4
What type of vulnerability is CVE-2022-38376?
CVE-2022-38376 is categorized as a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2022-38376 be exploited remotely?
Yes, CVE-2022-38376 can be exploited remotely through crafted HTTP requests.