CVE-2025-53608: XSS in LDAP server option
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox LDAP Server feature may allow an authenticated privileged attacker to execute code via crafted requests.
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated privileged attacker to execute code via crafted requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53608?
CVE-2025-53608 has a severe impact as it allows authenticated privileged attackers to execute code via crafted requests due to improper neutralization of input.
How do I fix CVE-2025-53608?
To remediate CVE-2025-53608, upgrade FortiSandbox to version 5.0.3 or later, or version 4.4.8 or later.
What software is affected by CVE-2025-53608?
CVE-2025-53608 affects FortiSandbox versions 4.0.x to 5.0.2.
What type of vulnerability is CVE-2025-53608?
CVE-2025-53608 is classified as a Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-53608 be exploited remotely?
Yes, CVE-2025-53608 can be exploited remotely if an attacker sends crafted requests to the vulnerable FortiSandbox LDAP Server feature.