CVE-2025-54353

Source
https://cve.org/CVERecord?id=CVE-2025-54353
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54353.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54353
Published
2025-12-09T18:15:53.973Z
Modified
2026-03-13T03:32:27.184021Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an attacker to perform an XSS attack via crafted HTTP requests.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "4.0.0"
            },
            {
                "last_affected": "4.0.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "4.2.0"
            },
            {
                "last_affected": "4.2.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "4.4.0"
            },
            {
                "last_affected": "4.4.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "5.0.0"
            },
            {
                "last_affected": "5.0.2"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54353.json"