ZeroHour

CVE-2021-24014

CVSS 3.1
6.1 medium
EPSS
<1%p47
Published
()
Modified
Description

Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.

Vendors
fortinet
Products
fortisandbox
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.