ID

VAR-E-201904-0300


CVE

cve_id:CVE-2018-1356

Trust: 0.3

sources: BID: 107838

TITLE

Fortinet FortiSandbox CVE-2018-1356 Cross Site Scripting Vulnerability

Trust: 0.3

sources: BID: 107838

DESCRIPTION

Fortinet FortiSandbox is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to perform unauthorized actions such as reading, modifying, or deleting content on behalf of the victim on the SharePoint site.

Trust: 0.3

sources: BID: 107838

AFFECTED PRODUCTS

vendor:fortinetmodel:fortisandboxscope:eqversion:2.5.2

Trust: 0.3

vendor:fortinetmodel:fortisandboxscope:eqversion:2.5.1

Trust: 0.3

vendor:fortinetmodel:fortisandboxscope:eqversion:2.5

Trust: 0.3

vendor:fortinetmodel:fortisandboxscope:eqversion:2.4.1

Trust: 0.3

vendor:fortinetmodel:fortisandboxscope:eqversion:2.4

Trust: 0.3

vendor:fortinetmodel:fortisandboxscope:neversion:3.0

Trust: 0.3

sources: BID: 107838

EXPLOIT

An attacker can exploit this issue by enticing an unsuspecting user to view a malicious webpage.

Trust: 0.3

sources: BID: 107838

PRICE

Free

Trust: 0.3

sources: BID: 107838

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 107838

CREDITS

Yasar Calay, Beyaz Bilgisayar Danmanlk, Hizmetleri Ltd.ti.

Trust: 0.3

sources: BID: 107838

EXTERNAL IDS

db:NVDid:CVE-2018-1356

Trust: 0.3

db:BIDid:107838

Trust: 0.3

sources: BID: 107838

REFERENCES

url:https://fortiguard.com/psirt/fg-ir-18-024

Trust: 0.3

url:http://www.fortinet.com/

Trust: 0.3

sources: BID: 107838

SOURCES

db:BIDid:107838

LAST UPDATE DATE

2022-07-27T09:26:51.728000+00:00


SOURCES UPDATE DATE

db:BIDid:107838date:2019-04-03T00:00:00

SOURCES RELEASE DATE

db:BIDid:107838date:2019-04-03T00:00:00