CVE-2023-41844: XSS
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.4 and above allows attacker to execute unauthorized code or commands via crafted HTTP requests in capture traffic endpoint.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41844?
CVE-2023-41844 is classified as a high severity vulnerability due to its potential for allowing cross-site scripting attacks.
How can I fix CVE-2023-41844?
To mitigate CVE-2023-41844, update Fortinet FortiSandbox to version 4.4.2 or later.
Who is affected by CVE-2023-41844?
CVE-2023-41844 affects Fortinet FortiSandbox versions 3.0.0 through 4.4.1.
What type of attack is possible with CVE-2023-41844?
CVE-2023-41844 allows for cross-site scripting (XSS) attacks, enabling unauthorized code execution on affected systems.
When was CVE-2023-41844 disclosed?
CVE-2023-41844 was publicly disclosed in 2023.