Multiple Reflected and Stored Cross-Site Scripting

Summary

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSandbox  may allow an authenticated attacker to perform cross-site scripting attack via crafted HTTP requests.

Version Affected Solution
FortiSandbox 5.0 Not affected Not Applicable
FortiSandbox 4.4 4.4.0 through 4.4.4 Upgrade to 4.4.5 or above
FortiSandbox 4.2 4.2.1 through 4.2.6 Upgrade to 4.2.7 or above
FortiSandbox 4.0 4.0.0 through 4.0.4 Upgrade to 4.0.5 or above
FortiSandbox 3.2 3.2 all versions Migrate to a fixed release
FortiSandbox 3.1 3.1 all versions Migrate to a fixed release
FortiSandbox 3.0 3.0 all versions Migrate to a fixed release

Fortinet in Q3/24 has remediated this issue in FortiSandbox Cloud version 24.1 and hence the customers need not perform any action.

Acknowledgement

Internally discovered and reported by Burnaby Infosec team and Lang Sun of Fortinet Software QA team.

Timeline

2025-02-11: Initial publication
2025-05-07: Clarify fix information for FortiSandbox Cloud product