{
    "id": "CVE-2023-48788",
    "published": "2024-03-12 15:15:46",
    "last_modified": "2026-06-17 06:34:58",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-89",
    "description": "A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets.",
    "epss_score": "0.98446",
    "epss_percentile": "0.99917",
    "kev": 1,
    "kev_due": "2024-04-15",
    "has_exploit": 0,
    "updated_at": "2026-09-26 18:33:54",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2024-04-15."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "forticlient_enterprise_management_server"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2023-48788",
        "date_added": "2024-03-25",
        "due_date": "2024-04-15",
        "vendor": "Fortinet",
        "product": "FortiClient EMS",
        "name": "Fortinet FortiClient EMS SQL Injection Vulnerability",
        "ransomware": 1
    },
    "exploits": [],
    "refs_list": [
        "https://fortiguard.com/psirt/FG-IR-24-007",
        "https://fortiguard.com/psirt/FG-IR-24-007",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-48788"
    ]
}