CVE-2018-1356 is a vulnerability in Fortinet Fortisandbox
Published on April 9, 2019
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
Products Associated with CVE-2018-1356
Want to know whenever a new CVE is published for Fortinet Fortisandbox? stack.watch will email you.
Affected Versions
Fortinet FortiSandbox:- Version 2.5.2 is affected.
- Version 2.5.1 is affected.
- Version 2.5.0 is affected.
- Version 2.4.1 is affected.
- Version 2.4.0 is affected.
Exploit Probability
EPSS
0.23%
Percentile
45.92%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.