Path traversal in GoAnywhere MFT 7.4.1 and Earlier
Vulnerability Description
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25156
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mohammed Eldeeb & Islam Elrfai, Spark Engineering Consultants
- vcth4nh from VcsLab of Viettel Cyber Security
More from Fortra
View All →Affected Vendor
Fortra
View all reports →