VYPR

GoAnywhere

by GoAnywhere

CVEs (2)

  • CVE-2024-25156MedMar 14, 2024
    risk 0.42cvss 6.5epss 0.00

    A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.

  • CVE-2021-46830MedJul 27, 2022
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain…