VYPR
High severity7.7NVD Advisory· Published Mar 1, 2022· Updated Jun 17, 2026

CVE-2021-32586

CVE-2021-32586

Description

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.

Affected products

4
  • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*range: <=5.4.12
    • cpe:2.3:a:fortinet:fortimail:7.0.0:*:*:*:*:*:*:*
    • (no CPE)range: <7.0.1
    • (no CPE)range: FortiMail before 7.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.