An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox version 4.4.0 and 4.2.0 through 4.2.4, and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.4 through 3.0.7 allows attacker to execute unauthorized code or commands via crafted HTTP requests.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2023-10-13T14:51:22.277Z

Updated: 2024-09-16T20:36:25.932Z

Reserved: 2023-09-04T08:12:52.814Z

Link: CVE-2023-41836

cve-icon Vulnrichment

Updated: 2024-08-02T19:09:49.060Z

cve-icon NVD

Status : Modified

Published: 2023-10-13T15:15:44.183

Modified: 2023-11-07T04:21:06.457

Link: CVE-2023-41836

cve-icon Redhat

No data.