PT-2026-32654 · Fortinet · Fortisandbox+1

Published

2026-04-14

·

Updated

2026-04-19

·

CVE-2025-61886

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FortiSandbox versions 5.0.0 through 5.0.4 FortiSandbox PaaS versions 5.0.0 through 5.0.4
Description An improper neutralization of input during web page generation allows a remote attacker to perform cross-site scripting (XSS) attacks using specially crafted HTTP requests. XSS is a flaw where an application includes untrusted data in a web page without proper validation or escaping, allowing the execution of malicious scripts in the victim's browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2026-05587
CVE-2025-61886

Affected Products

Fortisandbox
Fortisandbox Paas