VYPR
Medium severity6.5NVD Advisory· Published Mar 14, 2024· Updated Jun 17, 2026

CVE-2024-25156

CVE-2024-25156

Description

A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.

Affected products

4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.