CVE-2021-24015

HIGH

FortiMail 5.4.0-5.4.11 - Authenticated OS Command Injection via HTTP Request

Title source: llm
STIX 2.1

Description

An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-21-021

Scores

CVSS v3 7.2
EPSS 0.0031
EPSS Percentile 54.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
fortinet/fortimail 5.4.0 - 5.4.12
Published Jul 12, 2021
Tracked Since Feb 18, 2026