CVE-2025-54972

fortimail: Improper Neutralization of CRLF Sequences ('CRLF Injection') (CVE-2025-54972)

Affected

  • fortinet/fortimail between 7.0.0..7.4.6
  • fortinet/fortimail between 7.6.0..7.6.4

Description

An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted link

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

fortinetfortimail
7.0.0 – 7.4.67.6.0 – 7.6.4

Metrics

3.9
Source: nvd-v3
9.1 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
low
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-11-18 17:01 UTC
CWE-93

Weakness classes (CWE)

  • CWE-93Base

    Improper Neutralization of CRLF Sequences ('CRLF Injection')

    The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

    cwe.mitre.org →

References & sources