CVE-2018-1356
published 2019-04-09CVE-2018-1356: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.92%
56.4th percentile
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortisandbox | < 3.0.0 | 3.0.0 |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
| fortinet | fortisandbox | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g3q-pfmx-p47f: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3
ghsa_unreviewed·2022-05-14
CVE-2018-1356 [MEDIUM] CWE-79 GHSA-2g3q-pfmx-p47f: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
Fortinet
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut...
vendor_fortinet·2019-04-09·CVSS 6.1
CVE-2018-1356 [MEDIUM] CWE-79 A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut...
FG-IR-18-024: A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execut...
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
CVEs: CVE-2018-1356
CWEs: CWE-79
CVSS: 6.1 (medium)
Affected products: FortiSandbox, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-04-09
Published