Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
Fortinet FortiSandbox 跨站脚本漏洞
Vulnerability Description
Fortinet FortiSandbox是美国飞塔(Fortinet)公司的一款APT(高级持续性威胁)防护设备。该设备提供双重沙盒技术、动态威胁智能系统、实时控制面板和报告等功能。 Fortinet FortiSandbox 存在跨站脚本漏洞,该漏洞源于对用户提供的数据没有进行充分的清理。远程攻击者可以在易受攻击的网站上下文中诱使受害者跟随特制链接并在用户浏览器中执行任意 HTML 和脚本代码。 公开的漏洞允许远程攻击者执行跨站点脚本 (XSS) 攻击。
CVSS Information
N/A
Vulnerability Type
N/A