CVE 4.9 MEDIUM

CVE-2025-61886_CVE-2025-61886

4.9 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P/RL:O/RC:C

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

Basic Information

ID CVE-2025-61886
Source fortinet
Published Apr 14, 2026 at 15:38

Affected Product

Vendor Fortinet
Product FortiSandbox PaaS
Version 5.0.0
Affected Versions Fortinet FortiSandbox PaaS 5.0.0
Fortinet FortiSandbox 5.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.