CVE-2025-53681: SQL Injection
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53681?
CVE-2025-53681 is classified as a critical severity vulnerability.
How do I fix CVE-2025-53681?
To fix CVE-2025-53681, upgrade Fortinet FortiMail to a version later than 7.6.3, 7.4.5, or 7.2.8.
Who is affected by CVE-2025-53681?
CVE-2025-53681 affects Fortinet FortiMail versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.5, and 7.2.0 through 7.2.8.
What type of vulnerability is CVE-2025-53681?
CVE-2025-53681 is an SQL injection vulnerability allowing unauthorized command execution.
Can CVE-2025-53681 be exploited remotely?
Yes, CVE-2025-53681 can be exploited by an authenticated privileged attacker.