FG-IR-25-477: Reflected XSS in HA cluster
Published Dec 9, 2025
·Updated
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an attacker to perform an XSS attack via crafted HTTP requests.
Affected Software
4 affected componentsFixes available
Fortinet FortiSandbox>=5.0.0<=5.0.2
Fortinet FortiSandbox>=4.4.0<=4.4.7
Fortinet FortiSandbox>=4.2
Fortinet FortiSandbox>=4.0
Event History
Dec 9, 2025
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of FG-IR-25-477?
The severity of FG-IR-25-477 is classified as high due to the potential for XSS attacks.
2
How do I fix FG-IR-25-477?
To fix FG-IR-25-477, upgrade FortiSandbox to version 5.0.3 or higher for affected versions 5.0.0 to 5.0.2, and to version 4.4.8 or higher for 4.4.0 to 4.4.7.
3
What types of attacks does FG-IR-25-477 expose me to?
FG-IR-25-477 exposes systems to Cross-Site Scripting (XSS) attacks, allowing an attacker to inject malicious scripts.
4
Which versions of FortiSandbox are affected by FG-IR-25-477?
FG-IR-25-477 affects FortiSandbox versions 4.0 to 4.4.7 and 5.0.0 to 5.0.2.
5
Is FG-IR-25-477 a zero-day vulnerability?
FG-IR-25-477 is not a zero-day vulnerability as it has been disclosed and patches are available.