CVE-2025-54353: Reflected XSS in HA cluster
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an attacker to perform an XSS attack via crafted HTTP requests.
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54353?
CVE-2025-54353 is classified as a high severity vulnerability due to its potential to allow XSS attacks.
How do I fix CVE-2025-54353?
To fix CVE-2025-54353, upgrade FortiSandbox to at least version 5.0.3 or 4.4.8 depending on your current version.
What types of attacks can CVE-2025-54353 be exploited for?
CVE-2025-54353 can be exploited for Cross-site Scripting (XSS) attacks through crafted HTTP requests.
Which versions of FortiSandbox are affected by CVE-2025-54353?
Versions of FortiSandbox between 4.0.0 and 5.0.2 are affected by CVE-2025-54353.
Is there a workaround for CVE-2025-54353?
There is no official workaround for CVE-2025-54353; the recommended action is to update to a patched version.