CRLF Header Injection in webmail user GUI

Summary

A CRLF Header Injection vulnerability [CWE-93] in FortiMail user GUI may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Version Affected Solution
FortiMail 8.0 Not affected Not Applicable
FortiMail 7.6 7.6.0 through 7.6.3 Upgrade to 7.6.4 or above
FortiMail 7.4 7.4.0 through 7.4.5 Upgrade to 7.4.6 or above
FortiMail 7.2 7.2 all versions Migrate to a fixed release
FortiMail 7.0 7.0 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Jaguar Perlas from Fortinet Infosec team

Timeline

2025-11-18: Initial publication