First published: Tue Feb 11 2025(Updated: )
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox at least versions 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiSandbox Firmware | >=4.4.0<=4.4.4>=4.2.0<=4.2.6>=4.0.0<=4.0.4>=3.2.0<=3.2.4>=3.1.0<=3.1.5>=3.0.0<=3.0.7 | |
Fortinet FortiSandbox Firmware | >=4.4.0<=4.4.4 | |
Fortinet FortiSandbox Firmware | >=4.2.0<=4.2.6 | |
Fortinet FortiSandbox Firmware | >=4.0.0<=4.0.4 | |
Fortinet FortiSandbox Firmware | >=3.2 | |
Fortinet FortiSandbox Firmware | >=3.1 | |
Fortinet FortiSandbox Firmware | >=3.0 |
Please upgrade to FortiSandbox version 4.4.5 or above Please upgrade to FortiSandbox version 4.2.7 or above Please upgrade to FortiSandbox version 4.0.5 or above Please upgrade to FortiSandbox Cloud version 24.1 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27781 has a medium severity rating due to the potential for authenticated users to exploit the cross-site scripting vulnerability.
To fix CVE-2024-27781, update your Fortinet FortiSandbox to the latest version that addresses this vulnerability.
CVE-2024-27781 affects Fortinet FortiSandbox versions 4.4.0 through 4.4.4, 4.2.0 through 4.2.6, 4.0.0 through 4.0.4, 3.2.0 through 3.2.4, 3.1.0 through 3.1.5, and 3.0.0 through 3.0.7.
CVE-2024-27781 is a cross-site scripting (XSS) vulnerability caused by improper neutralization of input during web page generation.
No, CVE-2024-27781 requires authentication, meaning an attacker must have access to an authenticated session to exploit the vulnerability.