CVE-2018-1356: XSS
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the backurl parameter in the file scan component.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1356?
CVE-2018-1356 is a reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before version 3.0.
How does CVE-2018-1356 affect Fortinet FortiSandbox?
CVE-2018-1356 allows an attacker to execute unauthorized code or commands in Fortinet FortiSandbox by exploiting a reflected XSS vulnerability in the file scan component.
What is the severity of CVE-2018-1356?
CVE-2018-1356 has a severity rating of 6.1, which is categorized as medium.
How can I fix CVE-2018-1356?
To fix CVE-2018-1356, upgrade to Fortinet FortiSandbox version 3.0 or later.
Where can I find more information about CVE-2018-1356?
You can find more information about CVE-2018-1356 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/107838) and [FortiGuard Advisory FG-IR-18-024](https://fortiguard.com/advisory/FG-IR-18-024)