CVE-2023-36637: Fortinet FortiMail
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
Affected products
- Fortinet FortiMail: from 7.0.1, up to and including 7.0.5; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only
Published 2023-10-10. Last modified 2026-06-17.