OS command injection in GUI backup options
Summary
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSandbox GUI may allow an authenticated privileged attacker to execute unauthorized code or commands via crafted HTTP or HTTPS requests.
| Version | Affected | Solution |
|---|---|---|
| FortiSandbox 5.0 | 5.0.0 through 5.0.2 | Upgrade to 5.0.3 or above |
| FortiSandbox 4.4 | 4.4.0 through 4.4.7 | Upgrade to 4.4.8 or above |
| FortiSandbox 4.2 | 4.2 all versions | Migrate to a fixed release |
| FortiSandbox 4.0 | 4.0 all versions | Migrate to a fixed release |
| FortiSandbox Cloud 24 | 24.1 | Fortinet remediated this issue in 24.2 (not released) and hence customers do not need to perform any action. |
| FortiSandbox Cloud 23 | 23 all versions | Migrate to a fixed release |