First published: Fri Jul 09 2021(Updated: )
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiMail | <=5.4.12 | |
Fortinet FortiMail | >=5.6.1<6.0.11 | |
Fortinet FortiMail | >=6.2.0<6.2.7 | |
Fortinet FortiMail | >=6.4.0<6.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24007 is a vulnerability in FortiMail before 6.4.4 that allows a non-authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
CVE-2021-24007 is considered critical with a severity score of 9.8.
FortiMail versions between 5.4.12 and 6.4.4 are affected by CVE-2021-24007.
The vulnerability in CVE-2021-24007 can be exploited by a non-authenticated attacker through specially crafted HTTP requests.
Yes, a patch is available in FortiMail 6.4.4 to fix CVE-2021-24007.