FG-IR-25-454: OS command injection in GUI backup options
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-25-454?
The FG-IR-25-454 vulnerability is classified as an OS Command Injection risk and has significant implications for affected systems.
How do I fix FG-IR-25-454?
To fix FG-IR-25-454, you should upgrade FortiSandbox to version 5.0.3 or later if you're using versions 5.0.0 to 5.0.2, or version 4.4.8 or later for versions 4.4.0 to 4.4.7.
Who is affected by FG-IR-25-454?
FG-IR-25-454 affects various versions of FortiSandbox and FortiSandbox Cloud, particularly those prior to version 5.0.3 and 4.4.8.
What can be exploited in FG-IR-25-454?
FG-IR-25-454 allows authenticated privileged attackers to execute unauthorized commands on the server through specially crafted HTTP or HTTPS requests.
What type of attack does FG-IR-25-454 facilitate?
FG-IR-25-454 facilitates OS Command Injection attacks, which can lead to unauthorized code execution on vulnerable systems.