Reflected XSS in HA cluster

Summary

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox may allow an attacker to perform an XSS attack via crafted HTTP requests.

Version Affected Solution
FortiSandbox 5.0 5.0.0 through 5.0.2 Upgrade to 5.0.3 or above
FortiSandbox 4.4 4.4.0 through 4.4.7 Upgrade to 4.4.8 or above
FortiSandbox 4.2 4.2 all versions Migrate to a fixed release
FortiSandbox 4.0 4.0 all versions Migrate to a fixed release

Standalone FortiSandbox is not affected by this vulnerability.

Acknowledgement

Fortinet is pleased to thank Jason McFadyen of Trend Research working with Trend Micro Zero Day Initiative for reporting this vulnerability under responsible disclosure.

Timeline

2025-12-09: Initial publication