Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortinac  >> 9.4.0  Security Vulnerabilities
Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.
CVSS Score
7.1
EPSS Score
0.007
Published
2023-02-16
An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-02-16
Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests.
CVSS Score
6.1
EPSS Score
0.007
Published
2023-02-16


Contact Us

Shodan ® - All rights reserved