First published: Tue Apr 09 2019(Updated: )
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox Firmware | <3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1356 is a reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before version 3.0.
CVE-2018-1356 allows an attacker to execute unauthorized code or commands in Fortinet FortiSandbox by exploiting a reflected XSS vulnerability in the file scan component.
CVE-2018-1356 has a severity rating of 6.1, which is categorized as medium.
To fix CVE-2018-1356, upgrade to Fortinet FortiSandbox version 3.0 or later.
You can find more information about CVE-2018-1356 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/107838) and [FortiGuard Advisory FG-IR-18-024](https://fortiguard.com/advisory/FG-IR-18-024)