Medium severity5.4NVD Advisory· Published Aug 4, 2021· Updated Jun 17, 2026
CVE-2021-24014
CVE-2021-24014
Description
Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthenticated attacker to perform an XSS attack via specifically crafted request parameters.
Affected products
3cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: <=3.1.4
- (no CPE)range: <4.0.0
- (no CPE)range: FortiSandbox before 4.0.0
Patches
Vulnerability mechanics
References
1- fortiguard.com/advisory/FG-IR-20-209nvdVendor Advisory
News mentions
0No linked articles in our index yet.