CVE-2025-59922 – SQL Injection in Fortinet FortiClient EMS
In some cases, an attacker can supply crafted HTTP requests that are not properly neutralized, allowing execution of unauthorized SQL commands or other commands via the backend upon admin interaction. Affected versions are FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, FortiClientEMS 7.0. Affected users are advised to update to the latest version.
References:
