CVE-2019-16149

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:*

History

15 Jul 2025, 18:59

Type Values Removed Values Added
First Time Fortinet
Fortinet forticlientems
References () https://fortiguard.fortinet.com/psirt/FG-IR-19-072 - () https://fortiguard.fortinet.com/psirt/FG-IR-19-072 - Vendor Advisory
Summary
  • (es) Una neutralización incorrecta de la entrada durante la generación de páginas web en FortiClientEMS versión 6.2.0 puede permitir que un atacante remoto ejecute código no autorizado al inyectar un payload malicioso en el perfil de usuario de una instancia de FortiClient administrada por el sistema vulnerable.
CPE cpe:2.3:a:fortinet:forticlientems:*:*:*:*:*:*:*:*

28 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-28 10:15

Updated : 2025-07-15 18:59


NVD link : CVE-2019-16149

Mitre link : CVE-2019-16149

CVE.ORG link : CVE-2019-16149


JSON object : View

Products Affected

fortinet

  • forticlientems
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')