Fortinet FortiMail 7.2.0

CPE Details

Fortinet FortiMail 7.2.0
7.2.0
2022-11-03
14h58 +00:00
2022-11-03
15h03 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:fortinet:fortimail:7.2.0:*:*:*:*:*:*:*

Informations

Vendor

fortinet

Product

fortimail

Version

7.2.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-56497 2025-01-14 14h09 +00:00 An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 allows attacker to execute unauthorized code or commands via the CLI.
6.7
Medium
CVE-2023-36633 2023-11-14 18h07 +00:00 An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
5.4
Medium
CVE-2023-45582 2023-11-14 18h05 +00:00 An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.
7.3
High
CVE-2023-36637 2023-10-10 16h50 +00:00 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
5.4
Medium
CVE-2023-36556 2023-10-10 16h49 +00:00 An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.
8.8
High
CVE-2022-39945 2022-11-01 23h00 +00:00 An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains information via insecure direct object references (IDOR).
6.5
Medium
CVE-2021-32591 2021-12-08 10h56 +00:00 A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the password store to compromise the confidentiality of the encrypted secrets.
5.3
Medium