VULNERABILITY INTELLIGENCE
CVE-2025-53681
CVSS score6.3 MEDIUM
EPSS probability0.36%
CISA KEVNot currently listed
Published2026-05-12
Last modified2026-10-07
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Description
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Weakness classification
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Primary references
- psirt@fortinet.com — Vendor Advisory