CVE-2023-48788
Description
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Summary dbcve.org
SQL injection vulnerability in FortiClientEMS allows remote attackers to execute unauthorized code or commands through specially crafted SQL packets. The vulnerability exists due to improper neutralization of special elements in SQL commands, enabling attackers to inject malicious SQL queries.
Mitigation
Upgrade FortiClientEMS to version 7.2.3 or later (for 7.2.x) or 7.0.11 or later (for 7.0.x). If immediate patching is not possible, restrict network access to the EMS management interface and implement WAF/IPS rules for SQL injection detection.