Description
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Related CPE's
a
fortinet
fortimail
4
References
https://fortiguard.com/advisory/FG-IR-21-021
Vendor Advisory
https://fortiguard.com/advisory/FG-IR-21-021
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
7.2 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-07-12T12:15:08.057Z
4 years agoLast modified
2024-11-21T04:52:12.700Z
1 year ago