VYPR
Medium severity5.4NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026

CVE-2021-24014

CVE-2021-24014

Description

Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.

Affected products

3
  • cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: <=3.1.4
    • (no CPE)range: <4.0.0
    • (no CPE)range: FortiSandbox before 4.0.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.