Low severity3.5NVD Advisory· Published Apr 28, 2025· Updated Jun 17, 2026
CVE-2025-0049
CVE-2025-0049
Description
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
Affected products
3- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*Range: <7.8.0
<7.8.0+ 1 more
- (no CPE)range: <7.8.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- www.fortra.com/security/advisories/product-security/fi-2025-004nvdVendor Advisory
News mentions
0No linked articles in our index yet.