A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | FortiSandbox | 4.4.0, 23.4.4374, 23.4.4350, 23.3.4329, 23.1.4245, 22.2.4151, 22.2.4134, 22.1.4113, 21.4.4072, 21.3.4055 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| fortinet | fortisandbox paas | mitre_affected | 90% |
Updated description with new details and added tag for FortiSandbox PaaS.
Updated affected versions to include 4.4.9, marked exploit as available, and noted that the vulnerability is actively exploited.
Initial creation