CVE-2025-54972: CRLF Injection
An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54972?
The severity of CVE-2025-54972 is rated as high due to the risk of header injection that could lead to further attacks.
How do I fix CVE-2025-54972?
To fix CVE-2025-54972, upgrade FortiMail to the latest version that addresses this vulnerability.
What software is affected by CVE-2025-54972?
CVE-2025-54972 affects Fortinet FortiMail versions 7.6.0 to 7.6.3, 7.4.0 to 7.4.5, and all versions of 7.2 and 7.0.
What type of attack can CVE-2025-54972 facilitate?
CVE-2025-54972 can facilitate CRLF injection attacks, allowing attackers to manipulate HTTP response headers.
Is user interaction required for CVE-2025-54972 exploitation?
Yes, exploitation of CVE-2025-54972 typically requires user interaction, such as convincing a user to click on a malicious link.