CVE-2024-27781

Severity
9.0CRITICAL
EPSS
7.5%
top 8.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11

Description

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortisandbox3.0.04.0.5+2
CVEListV5fortinet/fortisandbox4.4.04.4.4+5

🔴Vulnerability Details

2
CVEList
CVE-2024-27781: An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 42025-02-11
GHSA
GHSA-cg8r-2vc3-jvc7: An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSandbox at least versions 42025-02-11

📋Vendor Advisories

1
Fortinet
Multiple Reflected and Stored Cross-Site Scripting2025-02-11
CVE-2024-27781 (CRITICAL CVSS 9) | An improper neutralization of input | cvebase.io