VYPR
Unrated severityNVD Advisory· Published Mar 13, 2024· Updated Sep 19, 2025

Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

CVE-2024-25153

Description

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.