CVE-2023-48788

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*
cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*

History

19 Mar 2024, 08:15

Type Values Removed Values Added
References
  • {'url': 'https://fortiguard.com/psirt/FG-IR-23-430', 'tags': ['Vendor Advisory'], 'source': 'psirt@fortinet.com'}
  • () https://fortiguard.com/psirt/FG-IR-24-007 -

15 Mar 2024, 14:52

Type Values Removed Values Added
CPE cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*
References () https://fortiguard.com/psirt/FG-IR-23-430 - () https://fortiguard.com/psirt/FG-IR-23-430 - Vendor Advisory
First Time Fortinet forticlient Enterprise Management Server
Fortinet
Summary
  • (es) Una neutralización inadecuada de elementos especiales utilizados en un comando sql ("inyección sql") en Fortinet FortiClientEMS versión 7.2.0 a 7.2.2, FortiClientEMS 7.0.1 a 7.0.10 permite a un atacante ejecutar código o comandos no autorizados a través de paquetes especialmente manipulados.

12 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-12 15:15

Updated : 2024-03-26 01:00


NVD link : CVE-2023-48788

Mitre link : CVE-2023-48788

CVE.ORG link : CVE-2023-48788


JSON object : View

Products Affected

fortinet

  • forticlient_enterprise_management_server
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')