CVE-2024-31488: XSS
An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 7.2.0 through 7.2.3 may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31488?
CVE-2024-31488 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-31488?
To fix CVE-2024-31488, upgrade FortiNAC to versions 9.4.5, 9.2.9, 9.1.11, 8.8.12, 8.7.7, or 7.2.4 or later.
Who is affected by CVE-2024-31488?
CVE-2024-31488 affects FortiNAC versions 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, 9.1.0 through 9.1.10, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, and 7.2.0 through 7.2.3.
What type of vulnerability is CVE-2024-31488?
CVE-2024-31488 is an improper neutralization of inputs during web page generation vulnerability.
Can CVE-2024-31488 lead to remote code execution?
Yes, CVE-2024-31488 may allow a remote authenticated attacker to perform stored cross-site scripting (XSS) attacks.