Medium severity6.5NVD Advisory· Published Mar 14, 2024· Updated Jun 17, 2026
CVE-2024-25156
CVE-2024-25156
Description
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
Affected products
4- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*Range: <7.4.2
<7.4.2+ 1 more
- (no CPE)range: <7.4.2
- (no CPE)range: 6.0.1
- Range: <7.4.2
Patches
Vulnerability mechanics
References
1- www.fortra.com/security/advisory/fi-2024-004nvdVendor Advisory
News mentions
0No linked articles in our index yet.