Fortinet Warns of Severe SQLi Vulnerability in FortiClientEMS Software
ID: 65daf6ff-866f-52ea-a8f8-d4f24a515013
STIX ID: report--65daf6ff-866f-52ea-a8f8-d4f24a515013
Feed Name: The Hacker News
Fortinet FortiClientEMS is affected by a critical SQL injection vulnerability (CVE-2023-48788, CVSS 9.3) that can allow unauthenticated attackers to achieve remote code execution as SYSTEM; Horizon3.ai published a PoC and Fortinet indicates the flaw is being exploited in the wild. The advisory lists affected FortiClientEMS, FortiOS, and FortiProxy versions, recommended upgrades, and additional unpatched/session-related issues in FortiWLM and FortiSIEM that could enable session hijacking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
