References https://nvd.nist.gov/vuln/detail/cve-2023-48788 https://www.fortiguard.com/psirt/FG-IR-24-007 https://www.secrss.com/articles/64450 https://qkl.seebug.org/vuldb/ssvid-99819 https://cve.circl.lu/vuln/cve-2023-48788 https://horizon3.ai/attack-research/attack-blogs/cve-2023-48788-fortinet-forticlientems-sql-injection-deep-dive/ https://redcanary.com/blog/threat-intelligence/cve-2023-48788/ https://www.tenable.com/cve/CVE-2023-48788 https://avd.aliyun.com/product?prod=forticlient_enterprise_management_server&page=-2 https://www.venustech.com.cn/new_type/aqtg/20240315/27168.html https://www.anquanke.com/post/id/302954 https://cve.imfht.com/poc_detail/2bdecc0534db5ce6ecbe40777de407cdc58aa152 https://www.secevery.com/toBugInfo?id=1772893308054577154
Related VulnerabilitiesPoCCVE-2026-21643: Fortinet FortiClientEMS 7.4.4 - SQL InjectionPoCCVE-2026-35616: FortiClient EMS - Authentication BypassPoCCVE-2023-48788: Fortinet Forticlient Endpoint Management Server - SQL InjectionFortinet FortiClient Enterprise Management Server 跨站脚本漏洞forticlient 漏洞FortiClient SSLVPN特权提升漏洞Fortinet FortiClient SSLVPN 信息泄露漏洞Fortinet FortiClient Linux SSLVPN 权限许可和访问控制漏洞Fortinet FortiClient SSLVPN Linux Client 本地提权漏洞