CVE-2023-41836: XSS
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.4, and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.4 through 3.0.7 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Other sources
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 through 4.2.4, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.4 through 3.0.7 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2023-41836?
CVE-2023-41836 is a vulnerability in Fortinet FortiSandbox that allows attackers to execute unauthorized code or commands through cross-site scripting.
What is the severity of CVE-2023-41836?
CVE-2023-41836 has a severity level of 6.1, which is considered medium.
Which software versions are affected by CVE-2023-41836?
Fortinet FortiSandbox versions 4.4.0, 4.2.0 through 4.2.4, 4.0.0 through 4.0.4, 3.2.0 through 3.2.4, 3.1.0 through 3.1.5, and 3.0.4 through 3.0.7 are affected by CVE-2023-41836.
How does CVE-2023-41836 work?
CVE-2023-41836 occurs due to an improper neutralization of input during web page generation, specifically a cross-site scripting vulnerability.
Is there a fix available for CVE-2023-41836?
To fix CVE-2023-41836, it is recommended to upgrade to a version of Fortinet FortiSandbox that is not affected by the vulnerability.