<?xml version="1.0" encoding="UTF-8"?>
<cvrf:cvrfdoc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
    <cvrf:DocumentTitle>Multiple reflected cross-site scripting vulnerabilities in portal UI</cvrf:DocumentTitle>
    <cvrf:DocumentType>Fortinet PSIRT Advisories</cvrf:DocumentType>
    <cvrf:DocumentPublisher Type="Vendor">
        <cvrf:ContactDetails>
            Fortinet PSIRT Contact:
            Website: https://fortiguard.fortinet.com/faq/psirt-contact
        </cvrf:ContactDetails>
     </cvrf:DocumentPublisher>
    <cvrf:DocumentTracking>
        <cvrf:Identification>
            <cvrf:ID>FG-IR-22-273</cvrf:ID>
        </cvrf:Identification>
        <cvrf:Status>Final</cvrf:Status>
        <cvrf:Version>1</cvrf:Version>
        <cvrf:RevisionHistory>
            <cvrf:Revision>
                <cvrf:Number>1</cvrf:Number>
                <cvrf:Date>2023-02-16T00:00:00</cvrf:Date>
                <cvrf:Description>Current version</cvrf:Description>
        </cvrf:Revision>
       </cvrf:RevisionHistory>
        <cvrf:InitialReleaseDate>2023-02-16T00:00:00</cvrf:InitialReleaseDate>
        <cvrf:CurrentReleaseDate>2023-02-16T00:00:00</cvrf:CurrentReleaseDate>
    </cvrf:DocumentTracking>
    <cvrf:DocumentNotes>
        <cvrf:Note Title="Summary" Type="Summary" Ordinal="1">
            Multiple improper neutralization of input during web page generation (&#39;Cross-site Scripting&#39;) vulnerabilities [CWE-79] in FortiNAC portal UI may allow an attacker to perform an XSS attack via crafted HTTP requests.
        </cvrf:Note>
        <cvrf:Note Title="Description" Type="General" Ordinal="2">
            None
        </cvrf:Note>
        <cvrf:Note Title="Impact" Type="General" Ordinal="3">
            Execute unauthorized code or commands
        </cvrf:Note>
        <cvrf:Note Title="Affected Products" Type="General" Ordinal="4">
            FortiNAC version 9.4.0 through 9.4.1FortiNAC 9.2 all versionsFortiNAC 9.1 all versionsFortiNAC 8.8 all versionsFortiNAC 8.7 all versionsFortiNAC 8.6 all versionsFortiNAC 8.5 all versionsFortiNAC 8.3 all versionsFortiNAC 7.2 all versions are not affected
        </cvrf:Note>
        <cvrf:Note Title="Solutions" Type="General" Ordinal="5">
            Please upgrade to FortiNAC-F version 7.2.0 or abovePlease upgrade to FortiNAC version 9.4.2 or above
        </cvrf:Note>
    </cvrf:DocumentNotes>
    <cvrf:Acknowledgments>
        <cvrf:Acknowledgment>
            <cvrf:Description>Internally discovered and reported by Théo Leleu of Fortinet Product Security team.</cvrf:Description>
        </cvrf:Acknowledgment>
    </cvrf:Acknowledgments>
    <ProductTree>
        <Branch Name="Fortinet" Type="Vendor">
            <Branch Name="FortiNAC" Type="Product Name">
                <Branch Name="9.4.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.4.1">FortiNAC 9.4.1</FullProductName>
                </Branch>
                <Branch Name="9.4.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.4.0">FortiNAC 9.4.0</FullProductName>
                </Branch>
                <Branch Name="9.2.8" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.8">FortiNAC 9.2.8</FullProductName>
                </Branch>
                <Branch Name="9.2.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.7">FortiNAC 9.2.7</FullProductName>
                </Branch>
                <Branch Name="9.2.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.6">FortiNAC 9.2.6</FullProductName>
                </Branch>
                <Branch Name="9.2.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.5">FortiNAC 9.2.5</FullProductName>
                </Branch>
                <Branch Name="9.2.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.4">FortiNAC 9.2.4</FullProductName>
                </Branch>
                <Branch Name="9.2.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.3">FortiNAC 9.2.3</FullProductName>
                </Branch>
                <Branch Name="9.2.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.2">FortiNAC 9.2.2</FullProductName>
                </Branch>
                <Branch Name="9.2.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.1">FortiNAC 9.2.1</FullProductName>
                </Branch>
                <Branch Name="9.2.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.2.0">FortiNAC 9.2.0</FullProductName>
                </Branch>
                <Branch Name="9.1.10" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.10">FortiNAC 9.1.10</FullProductName>
                </Branch>
                <Branch Name="9.1.9" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.9">FortiNAC 9.1.9</FullProductName>
                </Branch>
                <Branch Name="9.1.8" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.8">FortiNAC 9.1.8</FullProductName>
                </Branch>
                <Branch Name="9.1.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.7">FortiNAC 9.1.7</FullProductName>
                </Branch>
                <Branch Name="9.1.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.6">FortiNAC 9.1.6</FullProductName>
                </Branch>
                <Branch Name="9.1.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.5">FortiNAC 9.1.5</FullProductName>
                </Branch>
                <Branch Name="9.1.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.4">FortiNAC 9.1.4</FullProductName>
                </Branch>
                <Branch Name="9.1.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.3">FortiNAC 9.1.3</FullProductName>
                </Branch>
                <Branch Name="9.1.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.2">FortiNAC 9.1.2</FullProductName>
                </Branch>
                <Branch Name="9.1.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.1">FortiNAC 9.1.1</FullProductName>
                </Branch>
                <Branch Name="9.1.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-9.1.0">FortiNAC 9.1.0</FullProductName>
                </Branch>
                <Branch Name="8.8.11" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.11">FortiNAC 8.8.11</FullProductName>
                </Branch>
                <Branch Name="8.8.10" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.10">FortiNAC 8.8.10</FullProductName>
                </Branch>
                <Branch Name="8.8.9" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.9">FortiNAC 8.8.9</FullProductName>
                </Branch>
                <Branch Name="8.8.8" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.8">FortiNAC 8.8.8</FullProductName>
                </Branch>
                <Branch Name="8.8.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.7">FortiNAC 8.8.7</FullProductName>
                </Branch>
                <Branch Name="8.8.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.6">FortiNAC 8.8.6</FullProductName>
                </Branch>
                <Branch Name="8.8.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.5">FortiNAC 8.8.5</FullProductName>
                </Branch>
                <Branch Name="8.8.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.4">FortiNAC 8.8.4</FullProductName>
                </Branch>
                <Branch Name="8.8.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.3">FortiNAC 8.8.3</FullProductName>
                </Branch>
                <Branch Name="8.8.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.2">FortiNAC 8.8.2</FullProductName>
                </Branch>
                <Branch Name="8.8.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.1">FortiNAC 8.8.1</FullProductName>
                </Branch>
                <Branch Name="8.8.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.8.0">FortiNAC 8.8.0</FullProductName>
                </Branch>
                <Branch Name="8.7.6" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.6">FortiNAC 8.7.6</FullProductName>
                </Branch>
                <Branch Name="8.7.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.5">FortiNAC 8.7.5</FullProductName>
                </Branch>
                <Branch Name="8.7.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.4">FortiNAC 8.7.4</FullProductName>
                </Branch>
                <Branch Name="8.7.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.3">FortiNAC 8.7.3</FullProductName>
                </Branch>
                <Branch Name="8.7.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.2">FortiNAC 8.7.2</FullProductName>
                </Branch>
                <Branch Name="8.7.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.1">FortiNAC 8.7.1</FullProductName>
                </Branch>
                <Branch Name="8.7.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.7.0">FortiNAC 8.7.0</FullProductName>
                </Branch>
                <Branch Name="8.6.5" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.5">FortiNAC 8.6.5</FullProductName>
                </Branch>
                <Branch Name="8.6.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.4">FortiNAC 8.6.4</FullProductName>
                </Branch>
                <Branch Name="8.6.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.3">FortiNAC 8.6.3</FullProductName>
                </Branch>
                <Branch Name="8.6.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.2">FortiNAC 8.6.2</FullProductName>
                </Branch>
                <Branch Name="8.6.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.1">FortiNAC 8.6.1</FullProductName>
                </Branch>
                <Branch Name="8.6.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.6.0">FortiNAC 8.6.0</FullProductName>
                </Branch>
                <Branch Name="8.5.4" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.5.4">FortiNAC 8.5.4</FullProductName>
                </Branch>
                <Branch Name="8.5.3" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.5.3">FortiNAC 8.5.3</FullProductName>
                </Branch>
                <Branch Name="8.5.2" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.5.2">FortiNAC 8.5.2</FullProductName>
                </Branch>
                <Branch Name="8.5.1" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.5.1">FortiNAC 8.5.1</FullProductName>
                </Branch>
                <Branch Name="8.5.0" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.5.0">FortiNAC 8.5.0</FullProductName>
                </Branch>
                <Branch Name="8.3.7" Type="Product Version">
                    <FullProductName ProductID="FortiNAC-8.3.7">FortiNAC 8.3.7</FullProductName>
                </Branch>
            </Branch>
        </Branch>
    </ProductTree>
    <Vulnerability Ordinal="1">
        <Title>Multiple reflected cross-site scripting vulnerabilities in portal UI</Title>
        <cvrf:CVE>CVE-2022-38376</cvrf:CVE>
        <ProductStatuses>
            <Status Type="Known Affected">
                <ProductID>FortiNAC-9.4.1</ProductID>
                <ProductID>FortiNAC-9.4.0</ProductID>
                <ProductID>FortiNAC-9.2.8</ProductID>
                <ProductID>FortiNAC-9.2.7</ProductID>
                <ProductID>FortiNAC-9.2.6</ProductID>
                <ProductID>FortiNAC-9.2.5</ProductID>
                <ProductID>FortiNAC-9.2.4</ProductID>
                <ProductID>FortiNAC-9.2.3</ProductID>
                <ProductID>FortiNAC-9.2.2</ProductID>
                <ProductID>FortiNAC-9.2.1</ProductID>
                <ProductID>FortiNAC-9.2.0</ProductID>
                <ProductID>FortiNAC-9.1.10</ProductID>
                <ProductID>FortiNAC-9.1.9</ProductID>
                <ProductID>FortiNAC-9.1.8</ProductID>
                <ProductID>FortiNAC-9.1.7</ProductID>
                <ProductID>FortiNAC-9.1.6</ProductID>
                <ProductID>FortiNAC-9.1.5</ProductID>
                <ProductID>FortiNAC-9.1.4</ProductID>
                <ProductID>FortiNAC-9.1.3</ProductID>
                <ProductID>FortiNAC-9.1.2</ProductID>
                <ProductID>FortiNAC-9.1.1</ProductID>
                <ProductID>FortiNAC-9.1.0</ProductID>
                <ProductID>FortiNAC-8.8.11</ProductID>
                <ProductID>FortiNAC-8.8.10</ProductID>
                <ProductID>FortiNAC-8.8.9</ProductID>
                <ProductID>FortiNAC-8.8.8</ProductID>
                <ProductID>FortiNAC-8.8.7</ProductID>
                <ProductID>FortiNAC-8.8.6</ProductID>
                <ProductID>FortiNAC-8.8.5</ProductID>
                <ProductID>FortiNAC-8.8.4</ProductID>
                <ProductID>FortiNAC-8.8.3</ProductID>
                <ProductID>FortiNAC-8.8.2</ProductID>
                <ProductID>FortiNAC-8.8.1</ProductID>
                <ProductID>FortiNAC-8.8.0</ProductID>
                <ProductID>FortiNAC-8.7.6</ProductID>
                <ProductID>FortiNAC-8.7.5</ProductID>
                <ProductID>FortiNAC-8.7.4</ProductID>
                <ProductID>FortiNAC-8.7.3</ProductID>
                <ProductID>FortiNAC-8.7.2</ProductID>
                <ProductID>FortiNAC-8.7.1</ProductID>
                <ProductID>FortiNAC-8.7.0</ProductID>
                <ProductID>FortiNAC-8.6.5</ProductID>
                <ProductID>FortiNAC-8.6.4</ProductID>
                <ProductID>FortiNAC-8.6.3</ProductID>
                <ProductID>FortiNAC-8.6.2</ProductID>
                <ProductID>FortiNAC-8.6.1</ProductID>
                <ProductID>FortiNAC-8.6.0</ProductID>
                <ProductID>FortiNAC-8.5.4</ProductID>
                <ProductID>FortiNAC-8.5.3</ProductID>
                <ProductID>FortiNAC-8.5.2</ProductID>
                <ProductID>FortiNAC-8.5.1</ProductID>
                <ProductID>FortiNAC-8.5.0</ProductID>
                <ProductID>FortiNAC-8.3.7</ProductID>
            </Status>
        </ProductStatuses>
        <CVSSScoreSets>
            <ScoreSetV3>
                <BaseScoreV3>5.8</BaseScoreV3>
                <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:P/RL:X/RC:C</VectorV3>
            </ScoreSetV3>
        </CVSSScoreSets>
        <References Type="Self">
            <Reference>
                <URL>https://fortiguard.fortinet.com/psirt/FG-IR-22-273</URL>
                <Description>Multiple reflected cross-site scripting vulnerabilities in portal UI</Description>
            </Reference>Reference>
        </References>
    </Vulnerability>
</cvrf:cvrfdoc>