PT-2025-47360 · Fortinet · Fortimail
Published
2025-11-18
·
Updated
2025-11-19
·
CVE-2025-54972
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiMail versions 7.0 through 7.2
Fortinet FortiMail versions 7.4.0 through 7.4.5
Fortinet FortiMail versions 7.6.0 through 7.6.3
Description
A flaw exists in Fortinet FortiMail that allows for the injection of headers in responses. This occurs due to improper handling of carriage return and line feed (CRLF) sequences. An attacker can exploit this by convincing a user to click a specially designed link. The issue impacts the application's ability to properly sanitize user-supplied input, potentially leading to malicious header injection.
Recommendations
Update FortiMail versions prior to 7.6.4.
Update FortiMail versions prior to 7.4.6.
Update FortiMail versions prior to 7.2.1.
Update FortiMail versions prior to 7.0.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortimail