logo

FortiSandbox XSS Vulnerability Let Attackers Run Arbitrary Commands

ID: e5a51f23-e816-5fdb-af36-d3145ba71747

STIX ID: report--e5a51f23-e816-5fdb-af36-d3145ba71747

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet disclosed a high-severity reflected XSS vulnerability (CVE-2025-52436, CVSS 7.9) in the FortiSandbox GUI that allows unauthenticated attackers to inject JavaScript — potentially leading to remote code execution and full command-line access; affected PaaS versions include 5.0, 4.4, 4.2, and 4.0 with patches available (e.g., 4.4.8 and 5.0.5) and Fortinet recommending immediate upgrades and access restrictions until systems are remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.