Cross-Site Scripting Vulnerability in Fortinet FortiSandbox
CVE-2024-27781
6.9MEDIUM
What is CVE-2024-27781?
An input validation flaw in Fortinet FortiSandbox versions ranging from 3.0.0 to 4.4.4 enables authenticated attackers to execute unauthorized commands through specially crafted HTTP requests. The vulnerability occurs due to improper handling of input during web page generation, allowing the execution of malicious scripts that can compromise the security of the affected system.
Affected Version(s)
FortiSandbox 4.4.0 <= 4.4.4
FortiSandbox 4.2.0 <= 4.2.6
FortiSandbox 4.0.0 <= 4.0.4