CVE-2025-31366: Open Redirect and XSS in Web Filter warning page
An Improper Neutralization of Input During Web Page Generation and URL Redirection to Untrusted Site vulnerabilities [CWE-79, CWE-601] in FortiOS, FortiProxy and FortiSASE may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) or an open redirect attack via crafted HTTP requests.
Other sources
An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31366?
CVE-2025-31366 is classified as a high-severity vulnerability due to its potential impact on web security.
How do I fix CVE-2025-31366?
To remediate CVE-2025-31366, users should upgrade to the latest patched version of FortiOS, FortiProxy, or FortiSASE as specified by Fortinet.
Which versions of FortiOS are affected by CVE-2025-31366?
CVE-2025-31366 affects FortiOS versions 7.6.0 to 7.6.3, as well as versions 7.4.0 to 7.4.7, and all versions from 7.2 down to 6.4.
Can CVE-2025-31366 be exploited remotely?
Yes, CVE-2025-31366 can be exploited remotely, increasing the urgency for users to apply security updates.
Does CVE-2025-31366 affect FortiProxy?
Yes, CVE-2025-31366 also affects FortiProxy versions 7.6.0 to 7.6.3 and 7.4.0 to 7.4.9, among others.