#VU54787 Missing required cryptographic step in FortiMail - CVE-2021-24020
Published: July 13, 2021
FortiMail
Fortinet, Inc
Description
The vulnerability allows a remote attacker to bypass signature verification.
The vulnerability exists due to a missing cryptographic step in the implementation of the hash digest algorithm in FortiMail. A remote non-authenticated attacker can tamper with signed URLs by appending further data which allows bypass of signature verification.