Cross-site Scripting Vulnerability in Fortinet FortiSandbox Products
CVE-2025-52436
7.9HIGH
What is CVE-2025-52436?
The vulnerability in Fortinet FortiSandbox allows an unauthenticated attacker to exploit an improper input neutralization during web page generation. This can lead to executing arbitrary commands via specially crafted requests, posing significant risks for users of affected versions, including FortiSandbox 5.0.0 through 5.0.1 and 4.4.0 through 4.4.7, among others. Proper input validation and sanitization measures must be adopted to mitigate potential threats.
Affected Version(s)
FortiSandbox 5.0.0 <= 5.0.1
FortiSandbox 4.4.0 <= 4.4.7
FortiSandbox 4.2.1 <= 4.2.8