CVE-2021-24007: SQL Injection
Published Jul 9, 2021
·Updated
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected Software
4 affected components
Fortinet FortiMail<=5.4.12
Fortinet FortiMail>=5.6.1<6.0.11
Fortinet FortiMail>=6.2.0<6.2.7
Fortinet FortiMail>=6.4.0<6.4.4
Event History
Jul 9, 2021
CVE Published
via MITRE·06:37 PM
Data Sourced
via MITRE·06:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-24007?
CVE-2021-24007 is a vulnerability in FortiMail before 6.4.4 that allows a non-authenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
2
How severe is CVE-2021-24007?
CVE-2021-24007 is considered critical with a severity score of 9.8.
3
Which software versions are affected by CVE-2021-24007?
FortiMail versions between 5.4.12 and 6.4.4 are affected by CVE-2021-24007.
4
How can the vulnerability in CVE-2021-24007 be exploited?
The vulnerability in CVE-2021-24007 can be exploited by a non-authenticated attacker through specially crafted HTTP requests.
5
Is there a patch for CVE-2021-24007?
Yes, a patch is available in FortiMail 6.4.4 to fix CVE-2021-24007.