← back
CVE-2023-41844

CVE-2023-41844

CVSS 3.4 LOWEPSS 0.4%CWE-79
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.4EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Dec 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.4 and above allows attacker to execute unauthorized code or commands via crafted HTTP requests in capture traffic endpoint.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:F/RL:X/RC:C
Affected products
Fortinet · FortiSandbox

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →