Blind SSRF in API

Summary

A server-side request forgery vulnerability [CWE-918] in FortiClientEMS may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.

Version Affected Solution
FortiClientEMS 7.4 7.4.0 through 7.4.1 Upgrade to 7.4.3 or above
FortiClientEMS 7.2 7.2.0 through 7.2.6 Upgrade to 7.2.7 or above
FortiClientEMS 7.0 7.0 all versions Migrate to a fixed release
FortiClientEMS 6.4 6.4 all versions Migrate to a fixed release

Acknowledgement

Internally discovered and reported by Théo Leleu of Fortinet Product Security team.

Timeline

2025-06-10: Initial publication