Arbitrary file delete

Summary

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox may allow a low privileged attacker to delete arbitrary files via crafted http requests.

Version Affected Solution
FortiSandbox 4.4 4.4.0 Upgrade to 4.4.2 or above
FortiSandbox 4.2 4.2.1 through 4.2.5 Upgrade to 4.2.6 or above
FortiSandbox 4.0 4.0.0 through 4.0.3 Upgrade to 4.0.4 or above
FortiSandbox 3.2 3.2 all versions Migrate to a fixed release
FortiSandbox 3.1 3.1 all versions Migrate to a fixed release
FortiSandbox 3.0 3.0 all versions Migrate to a fixed release
FortiSandbox 2.5 2.5 all versions Migrate to a fixed release
FortiSandbox 2.4 2.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Adham El karn of Fortinet Product Security team.

Timeline

2023-10-13: Initial publication