CVE-2025-54353

Severity
6.1MEDIUM
EPSS
0.1%
top 69.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 9

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages2 packages

CVEListV5fortinet/fortisandbox5.0.05.0.2+3
NVDfortinet/fortisandbox4.0.04.0.6+3

🔴Vulnerability Details

2
CVEList
CVE-2025-54353: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox2025-12-09
GHSA
GHSA-xwrg-6m45-8r48: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox2025-12-09

📋Vendor Advisories

1
Fortinet
Reflected XSS in HA cluster2025-12-09
CVE-2025-54353 (MEDIUM CVSS 6.1) | An Improper Neutralization of Input | cvebase.io