Security Advisory
CVE-2024-23671
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A improper limitation of a pathname to a restricted directory (path traversal) vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands via crafted HTTP requests.