cbcvebase.
CVE-2023-26206
published 2024-02-15

CVE-2023-26206: An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and…

PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.47%
37.6th percentile
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the policy audit logs.

Affected

6 ranges
VendorProductVersion rangeFixed in
fortinetfortinac
fortinetfortinac
fortinetfortinac9.1.0 – 9.1.10
fortinetfortinac9.2.0 – 9.2.8
fortinetfortinac9.4.0 – 9.4.2
fortinetfortinet
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.