CVE-2023-22637

Severity
9.0CRITICAL
EPSS
0.7%
top 29.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateMay 4

Description

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger remote code execution via crafted licenses.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:HExploitability: 0.6 | Impact: 5.9

Affected Packages3 packages

NVDfortinet/fortinac8.7.09.4.3
CVEListV5fortinet/fortinac9.4.09.4.2+4

🔴Vulnerability Details

2
GHSA
GHSA-fjx8-gmr3-vg45: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 72023-05-04
CVEList
CVE-2023-22637: An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 72023-05-03

📋Vendor Advisories

1
Fortinet
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiN...2023-05-03
CVE-2023-22637 (CRITICAL CVSS 9) | An improper neutralization of input | cvebase.io