CVE-2024-27781
moderateAuthenticated Cross-Site Scripting in Fortinet FortiSandbox allows code execution
CVE-2024-27781 is an input neutralization flaw (cross-site scripting, CWE-79) in the Fortinet FortiSandbox web interface. An authenticated attacker sends crafted HTTP requests that get embedded into generated web pages without proper sanitization, allowing execution of unauthorized code or commands in the context of the affected web UI. Because the CVSS scope is changed (S:C) with high confidentiality, integrity and availability impacts, successful exploitation can compromise the victim's browser session and extend beyond the vulnerable component. The flaw affects FortiSandbox across the 3.0, 3.1, 3.2, 4.0, 4.2 and 4.4 release trains, so essentially any unpatched appliance on those versions is exposed to an attacker with valid credentials to the interface. Exploitation has not been observed publicly (no KEV entry, no known public PoC), but the EPSS score of 28.2% (98th percentile) indicates a materially elevated probability of exploitation within the next 30 days.
What to do: Upgrade FortiSandbox to a patched release beyond the affected ranges (newer than 4.4.4/4.2.6/4.0.4 for those trains, and off 3.x versions), following Fortinet's PSIRT advisory for CVE-2024-27781. In the interim, restrict access to the FortiSandbox web UI to trusted management networks and limit the number of privileged accounts. Prioritize patching on internet-reachable appliances and monitor for exploitation attempts given the elevated 28.2% EPSS score.
| fortinet FortiSandbox | 4.4.0 through 4.4.4 |
| fortinet FortiSandbox | 4.2.1 through 4.2.6 |
| fortinet FortiSandbox | 4.0.0 through 4.0.4 |
| fortinet FortiSandbox | 3.2, all versions |
| fortinet FortiSandbox | 3.1, all versions |
| fortinet FortiSandbox | 3.0, all versions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
- Vendors
- fortinet
- Products
- fortisandbox
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.