CVE-2019-16149
published 2025-03-28CVE-2019-16149: An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.27%
18.6th percentile
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticlient | — | — |
| fortinet | forticlientems | < 6.2.1 | 6.2.1 |
| fortinet | forticlientems | — | — |
| fortinet | forticlientems | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j8c2-6298-q92j: An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6
ghsa_unreviewed·2025-03-28
CVE-2019-16149 [MEDIUM] CWE-79 GHSA-j8c2-6298-q92j: An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
Fortinet
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attack...
vendor_fortinet·2025-03-28·CVSS 5.5
CVE-2019-16149 [MEDIUM] CWE-79 An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attack...
FG-IR-19-072: An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attack...
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.
CVEs: CVE-2019-16149
CWEs: CWE-79
CVSS: 5.5 (medium)
Affected products: FortiClient, FortiClientEMS, FortiClientems
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-28
Published