CVE-2023-22637: XSS
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger remote code execution via crafted licenses.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22637?
CVE-2023-22637 has a medium severity rating due to the risk of cross-site scripting that can be exploited in affected versions.
How do I fix CVE-2023-22637?
To fix CVE-2023-22637, upgrade affected FortiNAC or FortiNAC-F versions to the latest versions beyond 9.4.3 or 7.2.0.
What versions are affected by CVE-2023-22637?
CVE-2023-22637 affects FortiNAC versions 8.7 to 9.4.2 and FortiNAC-F version 7.2.0.
What type of vulnerability is CVE-2023-22637?
CVE-2023-22637 is classified as a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2023-22637?
Authenticated users of FortiNAC and FortiNAC-F can be affected by CVE-2023-22637 due to improper input handling.