CyberSec.Space Logo
Back to CVE Browser

CVE-2025-54972

MEDIUM
4.3
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-11-18
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Affected Platforms (CPE)

📦
Fortinet

Fortimail

>= 7.0.0 and < 7.4.6>= 7.6.0 and < 7.6.4

References & Advisories

Related Vulnerabilities