Vulnerabilities
Vulnerable Software
Fortinet:  >> Fortimail  >> 7.4.5  Security Vulnerabilities
An improper neutralization of crlf sequences ('crlf injection') in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link
CVSS Score
4.3
EPSS Score
0.0
Published
2025-11-18
A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
CVSS Score
5.3
EPSS Score
0.004
Published
2021-12-08


Contact Us

Shodan ® - All rights reserved