CVE-2023-36637: Fortinet FortiMail

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.

Affected products

  • Fortinet FortiMail: from 7.0.1, up to and including 7.0.5; version 7.2.0 only; version 7.2.1 only; version 7.2.2 only

Published 2023-10-10. Last modified 2026-06-17.