CVE-2023-41843: XSS
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
Other sources
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4.1 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41843?
The severity of CVE-2023-41843 is high.
How does CVE-2023-41843 affect Fortinet FortiSandbox?
CVE-2023-41843 affects Fortinet FortiSandbox versions 4.4.1 and 4.4.0 and 4.2.0 through 4.2.5 and 4.0.0 through 4.0.3.
Is CVE-2023-41843 a cross-site scripting vulnerability?
Yes, CVE-2023-41843 is a cross-site scripting vulnerability.
How can an attacker exploit CVE-2023-41843?
An attacker can exploit CVE-2023-41843 by executing unauthorized code or commands through crafted HTTP requests.
Where can I find more information about CVE-2023-41843?
You can find more information about CVE-2023-41843 at the following URL: https://fortiguard.com/psirt/FG-IR-23-273