FG-IR-26-141: Second-Order OS Command Injection via JSON Input on start vnc feature
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of FG-IR-26-141?
The severity of FG-IR-26-141 is classified as critical with a score of 9.1.
How do I fix FG-IR-26-141?
To fix FG-IR-26-141, ensure that you apply the latest security patches provided by Fortinet for FortiSandbox and related products.
What type of vulnerability is FG-IR-26-141?
FG-IR-26-141 is classified as a Second-Order OS Command Injection vulnerability.
Who is affected by FG-IR-26-141?
FG-IR-26-141 affects users of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS.
What can an attacker do with FG-IR-26-141?
An attacker exploiting FG-IR-26-141 can execute unauthorized commands on the system via specially crafted HTTP requests.