Описание
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated privileged attacker to execute code via crafted requests.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
4.8 Medium
CVSS3
Дефекты
Связанные уязвимости
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated privileged attacker to execute code via crafted requests.
Уязвимость компонента LDAP Server системы выявления и устранения угроз FortiSandbox, позволяющая нарушителю выполнить произвольный код
EPSS
4.8 Medium
CVSS3