Back to Database
Status published
Medium
CVE-2024-11922
Input Validation vulnerability in Web Client emails that do not go through Secure Mail
Vulnerability Description
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-11922
Credits & Attribution
No credits recorded in the NVD database.
More from Fortra
View All →CVE-2025-8450
Unrestricted File Upload in FileCatalyst
High
8.2
CVE-2025-8148
CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Medium
4.2
CVE-2025-5141
Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
Medium
5.5
CVE-2025-3871
Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier
Medium
5.3
CVE-2025-1241
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Medium
5.8
Affected Vendor
Fortra
View all reports →Affected Software
GoAnywhere MFT
Vulnerable Versions:
0
Timeline
Official Publish:
April 28th, 2025
Last Modified:
April 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L