← Back to browse · API

CVE-2023-48788

Severity
CRITICAL
CVSS
9.3
EPSS
0.97591
Risk score
59.16
CISA KEV
Yes
PoC
No
Published
2024-03-12
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2023-52821, GHSA-FV47-JG3J-5QF6
Products
Fortinet:FortiClient EMS, Fortinet:FortiClientEMS 7.0.1 ≤7.0.10, Fortinet:FortiClientEMS 7.2.0 ≤7.2.2
Sources
cisa.gov CVE-2023-48788
euvd EUVD-2023-52821

Description

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

References