Critical severity9.8CISA KEVNVD Advisory· Published Mar 12, 2024· Updated Jun 17, 2026
CVE-2023-48788
CVE-2023-48788
Description
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.
Affected products
3- cpe:2.3:a:fortinet:forticlient_enterprise_management_server:*:*:*:*:*:*:*:*Range: >=7.0.1,<7.0.11
7.2.0 through 7.2.2, 7.0.1 through 7.0.10+ 1 more
- (no CPE)range: 7.2.0 through 7.2.2, 7.0.1 through 7.0.10
- (no CPE)range: 7.2.0
Patches
Vulnerability mechanics
References
2- fortiguard.com/psirt/FG-IR-24-007nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
3- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central FlawThe Hacker News · Aug 10, 2026
- INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023The Hacker News · Jun 18, 2026
- INC Ransomware Thrives by Mastering the BasicsDark Reading · Jun 17, 2026