FG-IR-20-209: Cross-site scripting in FSA due to unsafe use of templating functions
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-20-209?
The severity of FG-IR-20-209 is classified as high due to the potential for unautheticated XSS attacks.
How do I fix FG-IR-20-209?
To fix FG-IR-20-209, update your FortiSandbox to the latest firmware version that addresses these vulnerabilities.
What type of vulnerability is FG-IR-20-209?
FG-IR-20-209 is identified as a Cross-Site Scripting (XSS) vulnerability stemming from improper input neutralization.
Who is affected by FG-IR-20-209?
The FG-IR-20-209 vulnerability affects users of Fortinet FortiSandbox software.
Can FG-IR-20-209 be exploited remotely?
Yes, FG-IR-20-209 can be exploited remotely by an unauthenticated attacker via specially crafted request parameters.