VYPR
High severity7.1NVD Advisory· Published Feb 16, 2023· Updated Jun 17, 2026

CVE-2023-22638

CVE-2023-22638

Description

Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.

Affected products

6
  • Fortinet/Fortinac4 versions
    cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortinac:*:*:*:*:*:*:*:*range: >=8.5.0,<=8.5.4
    • cpe:2.3:a:fortinet:fortinac:8.3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortinac:9.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:fortinet:fortinac:9.4.1:*:*:*:*:*:*:*
  • Fortinet/Fortinac Fllm-fuzzy2 versions
    <=9.4.1, <=9.2.6, <=9.1.8, <=8.8.11, <=8.7.6, <=8.6.5, <=8.5.4, <=8.3.7+ 1 more
    • (no CPE)range: <=9.4.1, <=9.2.6, <=9.1.8, <=8.8.11, <=8.7.6, <=8.6.5, <=8.5.4, <=8.3.7
    • (no CPE)range: 9.4.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.