MEDIUM🇵🇱 Wersja polska

CVE-2026-39812

CVSS 4.8v3.1pub. 2026-04-14upd. 2026-04-21

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
  • Fortinet Fortisandbox

    APP
    Fortinet
    5.0.0 – 5.0.6 (excl.)4.2.0 – 4.2.84.4.0 – 4.4.9 (excl.)
  • Fortinet Fortisandbox Cloud

    APP
    Fortinet
    5.0.45.0.522.2.4134 – 23.1.426023.3.4329 – 24.1.4436
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2026-25089CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Fortinet FortiSandbox — dostęp bez uwierzytelnienia

CVE-2026-39808CRITICAL9.8⚠ KEVPL ✓same product

Command Injection w Fortinet FortiSandbox umożliwiający RCE

CVE-2026-26083CRITICAL9.8PL ✓same product

Brak autoryzacji w Fortinet FortiSandbox umożliwia zdalne wykonanie kodu

CVE-2026-39813CRITICAL9.8PL ✓same product

Path Traversal w Fortinet FortiSandbox umożliwiający privilege escalation

CVE-2026-59835HIGH8.6PL ✓same product

Fortinet FortiSandbox — nieautoryzowany dostęp do serwera VNC maszyn wirtualnych