VDB
VAR-202305-0038
VAR-202305-0038
PUBLISHED
CVSS 5.900000095367432 MEDIUM
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Management would permit an authenticated attacker to trigger remote code execution via crafted licenses.
Risk Scores
CVSS v3.1
5.900000095367432
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiNAC | 9.4.0, 9.2.0, 9.1.0 |
Timeline
- Apr 22, 2026 CVE Published