S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Jan 6, 2025

CVE-2023-48788 Scanner

CVE-2023-48788 Scanner - SQL Injection vulnerability in Fortinet FortiClient Endpoint Management Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-48788
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
FortiClientEMSby Fortinet
7.2.0
forticlient_enterprise_management_serverby fortinet
7.2.0
forticlient_enterprise_management_serverby fortinet
7.2.0
Updated Sep 10, 2026View on NVD →
Detail

The Fortinet FortiClient Endpoint Management Server is a robust solution designed for enterprises to manage endpoint security efficiently. It is widely used by IT teams to ensure secure communication, software updates, and compliance with enterprise security protocols. This product helps organizations streamline endpoint security management and monitoring across multiple devices.

SQL Injection is a vulnerability that allows attackers to execute unauthorized SQL queries in the database backend. It is one of the most common and critical vulnerabilities, enabling attackers to access or manipulate data without proper authorization. This can lead to significant breaches in data confidentiality and system integrity.

The vulnerability lies in improper neutralization of special characters in SQL commands within specific endpoints of FortiClientEMS. Exploitation involves crafting malicious packets that bypass input sanitization checks, allowing attackers to interact with the database maliciously. Parameters such as `FCTUID` are among the vulnerable elements in the payload.

Exploitation of this vulnerability could lead to unauthorized database access, modification, or deletion of sensitive data, potentially causing severe operational and reputational damage. This may also pave the way for further exploitation within the affected network.

REFERENCES

Solution Advice
  • Apply patches or updates provided by Fortinet to address this vulnerability.
  • Ensure proper input validation and sanitization in all SQL queries to prevent injection.
  • Limit database permissions to minimize the impact of a successful attack.
  • Conduct regular vulnerability assessments and penetration testing on your systems.
  • Enable logging and monitoring to detect any abnormal database activity promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-48788 Scanner - SQL Injection vulnerability in Fortinet FortiClient Endpoint Management Server | S4E