CVE-2023-41681: XSS
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 and 2.5.0 through 2.5.2 and 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Other sources
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41681?
The severity of CVE-2023-41681 is high with a CVSS score of 6.1.
How does CVE-2023-41681 affect Fortinet FortiSandbox?
CVE-2023-41681 affects Fortinet FortiSandbox versions 2.4.1 through 4.4.1.
What is the vulnerability in CVE-2023-41681?
CVE-2023-41681 is a vulnerability related to improper neutralization of input during web page generation (cross-site scripting) in Fortinet FortiSandbox.
Are there any fixes available for CVE-2023-41681?
Yes, Fortinet has released a fix for CVE-2023-41681. Please refer to the official Fortinet advisory for more information.
Where can I find more information about CVE-2023-41681?
You can find more information about CVE-2023-41681 in the FortiGuard advisory: https://fortiguard.com/psirt/FG-IR-23-311.