PT-2025-47360 · Fortinet · Fortimail

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-54972

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiMail versions 7.0 through 7.2 Fortinet FortiMail versions 7.4.0 through 7.4.5 Fortinet FortiMail versions 7.6.0 through 7.6.3
Description A flaw exists in Fortinet FortiMail that allows for the injection of headers in responses. This occurs due to improper handling of carriage return and line feed (CRLF) sequences. An attacker can exploit this by convincing a user to click a specially designed link. The issue impacts the application's ability to properly sanitize user-supplied input, potentially leading to malicious header injection.
Recommendations Update FortiMail versions prior to 7.6.4. Update FortiMail versions prior to 7.4.6. Update FortiMail versions prior to 7.2.1. Update FortiMail versions prior to 7.0.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14871
CVE-2025-54972

Affected Products

Fortimail