VendorsFortinetfortimail5.2.3
Vulnerabilities

Fortinet Fortimail 5.2.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2017-7732
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via crafted HTTP requests.
Published 2017-10-26 · Modified
6.1EPSS 0.021
CVE-2017-3125
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.
Published 2017-04-12 · Modified
6.1EPSS 0.011
CVE-2015-3293
FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.
Published 2015-04-14 · Modified
4.0EPSS 0.010