Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-22638: Fortiguard

Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.11 and below, 8.7.6 and below, 8.6.5 and below, 8.5.4 and below, 8.3.7 and below may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.

CVE
#xss#vulnerability#web#auth

** PSIRT Advisories**

FortiNAC - Multiple Stored and Reflected XSS

Summary

Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC may allow an authenticated attacker to perform several XSS attacks via crafted HTTP GET requests.

Solutions

Please upgrade to FortiNAC-F version 7.2.0 or above,
Please upgrade to FortiNAC version 9.4.2 or above

Acknowledgement

Internally discovered and reported by Giulia Clerici of the Fortinet Product Security team.

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907