A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
2025-06-10T17:18:40.720
2025-07-16T15:17:53.827
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | fortinet | forticlientems | ≤ 6.4.9 | Yes |
Application | fortinet | forticlientems | ≤ 7.0.13 | Yes |
Application | fortinet | forticlientems | < 7.2.7 | Yes |
Application | fortinet | forticlientems | < 7.4.3 | Yes |