Medium severity6.1NVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026
CVE-2018-1356
CVE-2018-1356
Description
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.
Affected products
3cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: <3.0.0
- (no CPE)range: <3.0
- (no CPE)range: 2.5.2
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/107838nvdThird Party AdvisoryVDB Entry
- fortiguard.com/advisory/FG-IR-18-024nvdVendor Advisory
News mentions
0No linked articles in our index yet.