CVE-2021-24014

Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
References
Link Resource
https://fortiguard.com/advisory/FG-IR-20-209 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*

History

11 Aug 2021, 17:34

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*
CWE CWE-79
References (CONFIRM) https://fortiguard.com/advisory/FG-IR-20-209 - (CONFIRM) https://fortiguard.com/advisory/FG-IR-20-209 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1

04 Aug 2021, 19:18

Type Values Removed Values Added
New CVE

Information

Published : 2021-08-04 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-24014

Mitre link : CVE-2021-24014

CVE.ORG link : CVE-2021-24014


JSON object : View

Products Affected

fortinet

  • fortisandbox
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')