CVE-2025-52436: XSS via back button
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an unauthenticated attacker to execute commands via crafted requests. FortiSandbox PaaS versions 4.4.8 and 5.0.5 contains the fix for this vulnerability.
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52436?
CVE-2025-52436 is classified as a Cross-site Scripting vulnerability that can be exploited by unauthenticated attackers.
How do I fix CVE-2025-52436?
To remediate CVE-2025-52436, upgrade FortiSandbox to version 4.4.8 or 5.0.5.
Which FortiSandbox versions are affected by CVE-2025-52436?
FortiSandbox versions 4.4.0 to 4.4.7 and 5.0.0 to 5.0.1 are affected by CVE-2025-52436.
Can CVE-2025-52436 be exploited remotely?
Yes, CVE-2025-52436 can be exploited remotely by an unauthenticated attacker.
Is there a workaround for CVE-2025-52436?
There are no known workarounds for CVE-2025-52436; it is recommended to upgrade to a patched version.