Back to Database
Status published
Medium
CVE-2024-25154
Path Traversal in FileCatalyst Direct 3.8.8 and Earlier
Vulnerability Description
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25154
Credits & Attribution
No credits recorded in the NVD database.
References
More from Fortra
View All →CVE-2025-8450
Unrestricted File Upload in FileCatalyst
High
8.2
CVE-2025-8148
CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Medium
4.2
CVE-2025-5141
Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
Medium
5.5
CVE-2025-3871
Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier
Medium
5.3
CVE-2025-1241
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Medium
5.8
Affected Vendor
Fortra
View all reports →Affected Software
FileCatalyst
Vulnerable Versions:
3.8.6
Timeline
Official Publish:
March 13th, 2024
Last Modified:
August 12th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N