HIGH🇵🇱 Wersja polska

CVE-2025-52436

CVSS 8.8v3.1pub. 2026-02-10upd. 2026-02-18

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Fortinet Fortisandbox

    APP
    Fortinet
    4.0.0 – 4.4.8 (excl.)5.0.0 – 5.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSSAuth Bypass
CWE
References

Related vulnerabilities

CVE-2026-25089CRITICAL9.8⚠ KEVPL ✓same product

Command injection w Fortinet FortiSandbox — dostęp bez uwierzytelnienia

CVE-2026-39808CRITICAL9.8⚠ KEVPL ✓same product

Command Injection w Fortinet FortiSandbox umożliwiający RCE

CVE-2026-26083CRITICAL9.8PL ✓same product

Brak autoryzacji w Fortinet FortiSandbox umożliwia zdalne wykonanie kodu

CVE-2026-39813CRITICAL9.8PL ✓same product

Path Traversal w Fortinet FortiSandbox umożliwiający privilege escalation

CVE-2026-59835HIGH8.6PL ✓same product

Fortinet FortiSandbox — nieautoryzowany dostęp do serwera VNC maszyn wirtualnych