FG-IR-26-110: Multiple Stored XSS
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow a privileged attacker to perform a stored XSS attack via crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-110?
The FG-IR-26-110 vulnerability is classified as a medium severity issue due to its potential for stored cross-site scripting attacks.
How do I fix FG-IR-26-110?
To remediate FG-IR-26-110, upgrade FortiSandbox or FortiSandbox PaaS to version 5.0.6 or 4.4.9 depending on the affected version.
Which versions are affected by FG-IR-26-110?
FG-IR-26-110 affects FortiSandbox versions from 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, and all versions from 4.2.
What is stored cross-site scripting in FG-IR-26-110?
Stored cross-site scripting in FG-IR-26-110 occurs when an attacker can inject malicious scripts that are permanently stored and later executed in users' browsers.
Who can exploit the FG-IR-26-110 vulnerability?
FG-IR-26-110 can be exploited by a privileged attacker who is able to send crafted HTTP requests to the affected system.