CVE-2024-27781

Publication date

2025-02-11 16:09:12

Family

fortinet

State

PUBLISHED

Description

An improper neutralization of input during web page generation (cross-site scripting) in Fortinet FortiSandbox at least versions 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 and 4.0.0 through 4.0.4 and 3.2.0 through 3.2.4 and 3.1.0 through 3.1.5 and 3.0.0 through 3.0.7 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.