Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
March 14, 2024The Hacker NewsVulnerability / Network Security
Fortinet has warned of a critical security flaw impacting its FortiClientEMS software that could allow attackers to achieve code execution on affected systems.
“An improper neutralization of special elements used in an SQL Command (‘SQL Injection’) vulnerability [CWE-89] in FortiClientEMS may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted requests,” the company said in an advisory.
The vulnerability, tracked as CVE-2023-48788, carries a CVSS rating of 9.3 out of a maximum of 10. It impacts the following versions –
FortiClientEMS 7.2.0 through 7.2.2 (Upgrade to 7.2.3 or…Continue Reading