A client-side enforcement of server-side security in Fortinet FortiSandbox version 4.4.0 through 4.4.4 and 4.2.0 through 4.2.6 allows attacker to execute unauthorized code or commands via HTTP requests.
Solution:
The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Link | Tags |
---|---|
https://fortiguard.com/psirt/FG-IR-24-054 | vendor advisory |