Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.1, 8.2 and 8.3.0-8.3.2) allows an authenticated user to inject arbitrary web script or HTML via non-sanitized parameters "refresh" and "branchtotable" present in HTTP POST requests.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiWLC 跨站脚本漏洞
Vulnerability Description
Fortinet FortiWLC是美国飞塔(Fortinet)公司的一款无线局域网控制器。 Fortinet FortiWLC中存在跨站脚本漏洞。远程攻击者可借助HTTP POST请求中未过滤的‘refresh’和‘branchtotable’参数利用该漏洞注入任意的Web脚本或HTML。以下版本受到影响:Fortinet FortiWLC 6.1-2版本,6.1-4版本,6.1-5版本,7.0-7版本,7.0-8版本,7.0-9版本,7.0-10版本,8.0版本,8.1版本,8.2版本,8.3.0-8
CVSS Information
N/A
Vulnerability Type
N/A