CVE-2023-22638: XSS
Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this FortiNAC vulnerability?
The vulnerability ID is CVE-2023-22638.
What is the severity of vulnerability CVE-2023-22638?
The severity of vulnerability CVE-2023-22638 is high.
What is the affected software for vulnerability CVE-2023-22638?
The affected software for vulnerability CVE-2023-22638 is FortiNAC versions 8.3.7 and below, 8.5.4 and below, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.9 and below, 9.2.7 and below, 9.4.0 and below, 9.4.1 and below.
What is the CWE ID for vulnerability CVE-2023-22638?
The CWE ID for vulnerability CVE-2023-22638 is CWE-79.
How can an attacker exploit vulnerability CVE-2023-22638?
An authenticated attacker can perform several XSS attacks by exploiting vulnerability CVE-2023-22638.