OS Command Vulnerability in Fortinet FortiSandbox
CVE-2024-52961
8.6HIGH
What is CVE-2024-52961?
An OS Command injection vulnerability exists in Fortinet FortiSandbox where an authenticated attacker with read-only permissions can execute unauthorized commands. By sending specially crafted requests, the attacker exploits improper neutralization of special elements, resulting in potential unauthorized access to system functionalities. This vulnerability affects multiple versions of Fortinet FortiSandbox, underscoring the need for immediate patching and security measures.
Affected Version(s)
FortiSandbox 5.0.0
FortiSandbox 4.4.0 <= 4.4.6
FortiSandbox 4.2.0 <= 4.2.7