5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:F/RL:X/RC:C
Description
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.
Basic Information
ID
CVE-2025-54353
Source
fortinet
Published
Dec 9, 2025 at 17:19
Affected Product
Vendor
Fortinet
Product
FortiSandbox
Version
5.0.0
Affected Versions
Fortinet FortiSandbox 5.0.0
Fortinet FortiSandbox 4.4.0
Fortinet FortiSandbox 4.2.0
Fortinet FortiSandbox 4.0.0
Fortinet FortiSandbox 4.4.0
Fortinet FortiSandbox 4.2.0
Fortinet FortiSandbox 4.0.0