Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via specifically crafted HTTP requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 3.2.0 | 3.2.2 |
| fortinet / fortisandbox | - | 3.1.5 |