An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HFortinet Fortisandbox
APPFortinet4.0.0 – 4.4.8 (excl.)5.0.0 – 5.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSAuth Bypass
CWE
Related vulnerabilities
CVE-2026-25089CRITICAL9.8⚠ KEVPL ✓same product
Command injection w Fortinet FortiSandbox — dostęp bez uwierzytelnienia
CVE-2026-39808CRITICAL9.8⚠ KEVPL ✓same product
Command Injection w Fortinet FortiSandbox umożliwiający RCE
CVE-2026-26083CRITICAL9.8PL ✓same product
Brak autoryzacji w Fortinet FortiSandbox umożliwia zdalne wykonanie kodu
CVE-2026-39813CRITICAL9.8PL ✓same product
Path Traversal w Fortinet FortiSandbox umożliwiający privilege escalation
CVE-2026-59835HIGH8.6PL ✓same product
Fortinet FortiSandbox — nieautoryzowany dostęp do serwera VNC maszyn wirtualnych