PSIRT Advisory

XSS vulnerability in the ESS Profile and Radius Profile of FortiWLC

Summary

An improper neutralization of input vulnerability in FortiWLC may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.

Impact

Unauthorized code execution

Affected Products

FortiWLC version 8.5.1 and below.

Solutions

Please upgrade to FortiWLC version 8.5.2 or above.

Acknowledgement

Fortinet is pleased to thank Ali Ardic from Trend Micro for reporting this vulnerability under responsible disclosure