A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HFortinet Forticlientems
APPFortinet7.0.0 – 7.0.137.2.0 – 7.2.13 (excl.)7.4.0 – 7.4.6 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
Related vulnerabilities
CVE-2026-35616CRITICAL9.8⚠ KEVPL ✓same product
Fortinet FortiClientEMS — nieuwierzytelnione wykonanie kodu (Auth Bypass)
CVE-2026-21643CRITICAL9.8⚠ KEVPL ✓same product
SQL Injection w Fortinet FortiClientEMS — nieautoryzowane wykonanie kodu
CVE-2026-59836HIGH7.5PL ✓same product
Nieprawidłowa walidacja certyfikatów w Fortinet FortiClientEMS
CVE-2025-59922HIGH7.2same product
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89]...
CVE-2024-23106HIGH8.1same product
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through...