LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2025-53681

fortinet · fortimail

Published
CVSS7.2
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.

References

← Back to the CVE Tracker

Our coverage of CVE-2025-53681

No stories yet. This page updates automatically when we publish reporting that references CVE-2025-53681.