Back to Database
Status published
High
CVE-2025-8450
Unrestricted File Upload in FileCatalyst
Vulnerability Description
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8450
Credits & Attribution
No credits recorded in the NVD database.
More from Fortra
View All →CVE-2025-8148
CVE-2025-8148 Improper Access Control in SFTP service of GoAnywhere MFT
Medium
4.2
CVE-2025-5141
Core Privileged Access Manager (BoKS) Leakage of Sensitive Data via the Cache
Medium
5.5
CVE-2025-3871
Broken Access Control Leads to Limited Denial of Service in GoAnywhere MFT 7.8.0 and earlier
Medium
5.3
CVE-2025-1241
Encryption vulnerable to brute-force decryption in GoAnywhere MFT
Medium
5.8
CVE-2025-14362
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
High
7.3
Affected Vendor
Fortra
View all reports →Affected Software
FileCatalyst
Vulnerable Versions:
5.1.6
Timeline
Official Publish:
August 19th, 2025
Last Modified:
August 29th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
MITRE ATT&CK TTPs
T1190
Exploit Public-Facing Application
Initial Access
T1505.003
Web Shell
Persistence
T1105
Ingress Tool Transfer
Command and Control
T1059
Command and Scripting Interpreter
Execution
T1565.002
Stored Data Manipulation
Impact
T1078
Valid Accounts
Persistence
T1136
Create Account
Persistence
T1098
Account Manipulation
Privilege Escalation
T1021
Remote Services
Lateral Movement