Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gw24-hwf5-92h2

Опубликовано: 09 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

EPSS

Процентиль: 98%
0.23393
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость графического пользовательского интерфейса системы выявления и устранения угроз Fortinet FortiSandbox и FortiSandbox Cloud, позволяющая нарушителю выполнить произвольные команды посредством специально сформированных HTTP-запросов

EPSS

Процентиль: 98%
0.23393
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78