Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 3.2.0 | 3.2.3 |
| fortinet / fortisandbox | 3.1.0 | 3.1.5 |