VYPR

MFT

by GoAnywhere

CVEs (2)

  • CVE-2024-25157MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

  • CVE-2021-46830MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain…