CVE-2019-16149: Fortinet FortiClient EMS

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system.

Affected products

  • Fortinet FortiClient EMS: before 6.2.1 (fixed in 6.2.1)

Published 2025-03-28. Last modified 2026-06-17.