PT-2025-41955 · Fortinet · Fortisase+2
Published
2025-10-14
·
Updated
2025-10-22
·
CVE-2025-47890
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 6.4 through 7.6.2
FortiProxy versions 7.0 through 7.6.3
FortiSASE version 25.2.a
Description
An URL Redirection to Untrusted Site issue exists in FortiOS, FortiProxy, and FortiSASE. This allows an unauthenticated attacker to perform an open redirect attack via crafted HTTP requests. The issue is related to improper handling of redirects to untrusted sites, potentially leading to phishing or other malicious activities.
Recommendations
FortiOS versions prior to 7.6.2 should be updated.
FortiProxy versions prior to 7.6.3 should be updated.
FortiSASE version 25.2.a should be updated.
Fix
Open Redirect
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fortios
Fortiproxy
Fortisase