SQL Injection vulnerabilities in FortiMail
Summary
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
Affected Products
FortiMail version 6.4.3 and below.
FortiMail version 6.2.6 and below.
FortiMail version 6.0.10 an below.
FortiMail version 5.4.12 and below.
Solutions
Upgrade to version 6.4.4 or higher.
Upgrade to version 6.2.7 or higher.
Upgrade to version 6.0.11 or higher.
5.4 Fix to be confirmed.
Acknowledgement
Internally discovered and reported by Giuseppe Cocomazzi of the Fortinet PSIRT Team.Timeline
2021-07-07: Initial publication