First published: Thu Feb 16 2023(Updated: )
Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiNAC | >=8.5.0<=8.5.4 | |
Fortinet FortiNAC | >=8.6.0<9.4.2 | |
Fortinet FortiNAC | =8.3.7 |
Please upgrade to FortiNAC-F version 7.2.0 or above Please upgrade to FortiNAC version 9.4.2 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38376 has been rated as a high severity vulnerability due to its potential to allow XSS attacks.
To fix CVE-2022-38376, upgrade Fortinet FortiNAC to version 9.4.1 or later.
CVE-2022-38376 affects Fortinet FortiNAC versions from 8.3.7 up to but not including 9.4.2, and from 8.5.0 to 8.5.4.
CVE-2022-38376 is categorized as a Cross-Site Scripting (XSS) vulnerability.
Yes, CVE-2022-38376 can be exploited remotely through crafted HTTP requests.