A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://fortiguard.fortinet.com/psirt/FG-IR-23-342 |
|
History
Wed, 16 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fortinet
Fortinet forticlientems |
|
| CPEs | cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fortinet
Fortinet forticlientems |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 11 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fortinet
Published: 2025-06-10T16:36:19.062Z
Updated: 2025-06-11T14:43:41.910Z
Reserved: 2023-11-19T19:58:38.554Z
Link: CVE-2023-48786
Updated: 2025-06-11T14:43:38.231Z
Status : Analyzed
Published: 2025-06-10T17:18:40.720
Modified: 2025-07-16T15:17:53.827
Link: CVE-2023-48786
No data.