CVE-2018-1356: Fortinet FortiSandbox

Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.

A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.

Affected products

  • Fortinet FortiSandbox: before 3.0.0 (fixed in 3.0.0)

Published 2019-04-09. Last modified 2026-06-17.