← Vulnerability feed

Vulnerability record · CVE-2024-27781 · published 11 February 2025

CVE-2024-27781: Fortinet fortisandbox cross-site scripting vulnerability

Fortinet · Fortisandbox

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

9.0 CVSS 3.1 Critical EPSS 28% · top 1.9% CWE-79 · Cross-site scripting
9.0CVSS 3.1 base score
28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-27781 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-25089Fortinet FortiSandbox unauthenticated OS command injectionFortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS fail to neutralize special elements in HTTP request handling, allowing OS command injection (C…KEVEPSS 76%analysed9.8CVE-2026-39808Fortinet FortiSandbox OS command injectionFortiSandbox 4.4.0 through 4.4.8 fails to neutralize special elements used in OS commands, allowing command injection. The flaw is remotely reachable…KEVEPSS 47%analysed9.8CVE-2026-26083Fortinet fortisandbox missing authorization vulnerabilityA missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…EPSS 0.50%9.8CVE-2026-39813Fortinet fortisandbox vulnerabilityA path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…EPSS 0.72%9.6CVE-2025-52436Fortinet fortisandbox cross-site scripting vulnerabilityAn Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…EPSS 6.5%8.8CVE-2025-53949Fortinet fortisandbox os command injection vulnerabilityAn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…EPSS 17%8.8CVE-2021-26105Fortinet fortisandbox out-of-bounds write vulnerabilityA stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allo…EPSS 0.50%8.8CVE-2024-54026Fortinet fortisandbox sql injection vulnerabilityAn improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.…EPSS 0.41%

Source: NIST National Vulnerability Database (record CVE-2024-27781), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.