FG-IR-24-063: Multiple Reflected and Stored Cross-Site Scripting
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSandbox may allow an authenticated attacker to perform cross-site scripting attack via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-24-063?
The severity of FG-IR-24-063 is classified as high, due to the potential for authenticated attackers to execute cross-site scripting attacks.
How do I fix FG-IR-24-063?
To fix FG-IR-24-063, upgrade the FortiSandbox to the latest version that is not affected, with the minimum versions being 4.4.5, 4.2.7, and 4.0.5 depending on your current version.
What types of attacks are possible with FG-IR-24-063?
FG-IR-24-063 may allow an authenticated attacker to perform cross-site scripting attacks, potentially leading to data theft or user session hijacking.
Which versions of FortiSandbox are affected by FG-IR-24-063?
FG-IR-24-063 affects FortiSandbox versions between 4.4.0 and 4.4.4, 4.2.0 and 4.2.6, and 4.0.0 and 4.0.4, as well as earlier versions like 3.2, 3.1, and 3.0.
Is FG-IR-24-063 a risk for all FortiSandbox users?
Yes, FG-IR-24-063 poses a risk for all FortiSandbox users running the affected versions, making it imperative to update to secure releases.