OS Command Injection Vulnerability in FortiSandbox by Fortinet
CVE-2021-26097
8.8HIGH
What is CVE-2021-26097?
An improper neutralization of special elements in FortiSandbox allows authenticated attackers to exploit the web GUI, facilitating unauthorized command execution through specially crafted HTTP requests. This vulnerability affects multiple versions across FortiSandbox, underscoring the importance of promptly addressing security measures to mitigate potential exploitation risks.
Affected Version(s)
Fortinet FortiSandbox FortiSandbox 3.2.2, 3.2.1, 3.2.0, 3.1.4, 3.1.3, 3.1.2, 3.1.1, 3.1.0, 3.0.6, 3.0.5, 3.0.4, 3.0.3, 3.0.2, 3.0.1, 3.0.0