Unrated severityNVD Advisory· Published Mar 13, 2024· Updated Sep 19, 2025
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
CVE-2024-25153
Description
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <= 5.1.6.114
<= 5.1.6.114+ 1 more
- (no CPE)range: <= 5.1.6.114
- (no CPE)range: 5.1.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.