CVE-2023-48788

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:32

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-24-007 - Vendor Advisory () https://fortiguard.com/psirt/FG-IR-24-007 - Vendor Advisory

23 May 2024, 18:00

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-24-007 - () https://fortiguard.com/psirt/FG-IR-24-007 - Vendor Advisory

19 Mar 2024, 08:15

Type Values Removed Values Added
References
  • {'url': 'https://fortiguard.com/psirt/FG-IR-23-430', 'tags': ['Vendor Advisory'], 'source': 'psirt@fortinet.com'}
  • () https://fortiguard.com/psirt/FG-IR-24-007 -

15 Mar 2024, 14:52

Type Values Removed Values Added
References () https://fortiguard.com/psirt/FG-IR-23-430 - () https://fortiguard.com/psirt/FG-IR-23-430 - Vendor Advisory
Summary
  • (es) Una neutralización inadecuada de elementos especiales utilizados en un comando sql ("inyección sql") en Fortinet FortiClientEMS versión 7.2.0 a 7.2.2, FortiClientEMS 7.0.1 a 7.0.10 permite a un atacante ejecutar código o comandos no autorizados a través de paquetes especialmente manipulados.
CPE cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*
First Time Fortinet forticlient Enterprise Management Server
Fortinet

12 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 15:15

Updated : 2024-11-21 08:32


NVD link : CVE-2023-48788

Mitre link : CVE-2023-48788

CVE.ORG link : CVE-2023-48788


JSON object : View

Products Affected

fortinet

  • forticlient_enterprise_management_server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')