CVE-2025-61886: Reflected XSS in Operation Center
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow an attacker to perform an XSS attack via crafted HTTP requests.
Other sources
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61886?
The severity of CVE-2025-61886 is medium with a CVSS score of 5.4.
How do I fix CVE-2025-61886?
To fix CVE-2025-61886, upgrade to FortiSandbox PaaS version 5.0.5 or above and FortiSandbox version 5.0.5 or above.
What types of systems are affected by CVE-2025-61886?
CVE-2025-61886 affects Fortinet FortiSandbox and FortiSandbox Cloud services.
What type of vulnerability is CVE-2025-61886?
CVE-2025-61886 is classified as a Cross-site Scripting (XSS) vulnerability.
What impact can an attacker have by exploiting CVE-2025-61886?
An attacker exploiting CVE-2025-61886 can perform an XSS attack via crafted HTTP requests.