FG-IR-26-091: XSS in LDAP server option
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox LDAP Server feature may allow an authenticated privileged attacker to execute code via crafted requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-091?
The FG-IR-26-091 vulnerability is considered high severity due to its potential for Cross-site Scripting (XSS) which can lead to code execution.
How do I fix FG-IR-26-091?
To fix FG-IR-26-091, update your FortiSandbox to version 5.0.3 or later, or 4.4.8 or later, depending on your current version.
Who is affected by FG-IR-26-091?
The FG-IR-26-091 vulnerability affects FortiSandbox installations that are running versions from 4.0 to 5.0.2.
What type of attack can FG-IR-26-091 facilitate?
FG-IR-26-091 can facilitate Cross-site Scripting (XSS) attacks, allowing authenticated privileged attackers to execute unauthorized code.
Is FG-IR-26-091 present in all FortiSandbox versions?
No, FG-IR-26-091 is only present in specific vulnerable versions of FortiSandbox prior to the remediation updates.