Stored and reflected XSS

Summary

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiNAC may allow a remote authenticated attacker to perform stored and reflected cross site scripting (XSS) attack via crafted HTTP requests.

Version Affected Solution
FortiNAC 9.4 9.4.0 through 9.4.4 Upgrade to 9.4.5 or above
FortiNAC 9.2 9.2 all versions Migrate to a fixed release
FortiNAC 9.1 9.1 all versions Migrate to a fixed release
FortiNAC 8.8 8.8 all versions Migrate to a fixed release
FortiNAC 8.7 8.7 all versions Migrate to a fixed release
FortiNAC 7.4 Not affected Not Applicable
FortiNAC 7.2 7.2.0 through 7.2.3 Upgrade to 7.2.4 or above

Acknowledgement

Internally discovered and reported by Heidi White and Brian Bull of Fortinet QA team.

Timeline

2024-05-14: Initial publication