Medium severity5.9NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-31487
CVE-2024-31487
Description
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandbox 2.5 all versions, FortiSandbox 2.4 all versions allows attacker to information disclosure via crafted http requests.
Affected products
3cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:fortinet:fortisandbox:*:*:*:*:*:*:*:*range: >=2.4.0,<4.2.7
- cpe:2.3:a:fortinet:fortisandbox:4.4.4:*:*:*:*:*:*:*range: 4.4.0
- (no CPE)range: 4.4.0 through 4.4.4, 4.2.1 through 4.2.6, 4.0 all versions, 3.2 all versions, 3.1 all versions, 3.0 all versions, 2.5 all versions, 2.4 all versions
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-24-060nvdVendor Advisory
News mentions
0No linked articles in our index yet.