ZeroHour

CVE-2021-24015

CVSS 3.1
8.8 high
EPSS
1%p65
Published
()
Modified
Description

An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

Vendors
fortinet
Products
fortimail
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.