CVE-2025-47890: Open Redirect and XSS in Web Filter warning page
An Improper Neutralization of Input During Web Page Generation and URL Redirection to Untrusted Site vulnerabilities [CWE-79, CWE-601] in FortiOS, FortiProxy and FortiSASE may allow an unauthenticated attacker to perform a reflected cross site scripting (XSS) or an open redirect attack via crafted HTTP requests.
Other sources
An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSASE 25.2.a may allow an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.4.9 - Upgrade
Upgrade
FortiOSto a version that resolves this vulnerability.Fixed in 7.6.4 - Upgrade
Upgrade
FortiProxyto a version that resolves this vulnerability.Fixed in 7.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47890?
CVE-2025-47890 is classified as a high-severity vulnerability due to its potential to redirect users to untrusted sites.
How do I fix CVE-2025-47890?
To fix CVE-2025-47890, upgrade your FortiOS, FortiProxy, or FortiSASE to the latest patched versions as recommended by Fortinet.
Which products are affected by CVE-2025-47890?
CVE-2025-47890 affects FortiOS versions 7.6.0 to 7.6.2 and several earlier versions, as well as FortiProxy 7.6.0 to 7.6.3 and FortiSASE 25.2.a.
What type of vulnerability is CVE-2025-47890?
CVE-2025-47890 is an URL Redirection to Untrusted Site vulnerability, categorized under CWE-601.
Can CVE-2025-47890 be exploited remotely?
Yes, CVE-2025-47890 can be exploited remotely, allowing an attacker to redirect users to malicious sites.