A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
| Software | From | Fixed in |
|---|---|---|
| fortinet / fortisandbox | 4.4.0 | 4.4.5 |
| fortinet / fortisandbox | 4.2.0 | 4.2.7 |