XSS vulnerability in the ESS Profile and Radius Profile of FortiWLC
Fortinet PSIRT Advisories
Fortinet PSIRT Contact:
Website: https://fortiguard.fortinet.com/faq/psirt-contact
FG-IR-20-016
Final
1
1
2020-06-21T00:00:00
Current version
2020-06-21T00:00:00
2020-06-21T00:00:00
An improper neutralization of input vulnerability in FortiWLC may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.
Unauthorized code execution
FortiWLC version 8.5.1 and below.
Please upgrade to FortiWLC version 8.5.2 or above.
Fortinet is pleased to thank Ali Ardic from Trend Micro for reporting this vulnerability under responsible disclosure
FortiWLC 8.5.1
XSS vulnerability in the ESS Profile and Radius Profile of FortiWLC
CVE-2020-9288
FortiWLC-8.5.1
4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N/E:F/RL:X/RC:X
https://fortiguard.fortinet.com/psirt/FG-IR-20-016
XSS vulnerability in the ESS Profile and Radius Profile of FortiWLC
Reference>