CVE-2023-48786
10.06.2025, 17:18
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
Vendor | Product | Version |
---|---|---|
fortinet | forticlientems | 6.4.0 ≤ 𝑥 ≤ 6.4.9 |
fortinet | forticlientems | 7.0.0 ≤ 𝑥 ≤ 7.0.13 |
fortinet | forticlientems | 7.2.0 ≤ 𝑥 < 7.2.7 |
fortinet | forticlientems | 7.4.0 ≤ 𝑥 < 7.4.3 |
𝑥
= Vulnerable software versions