Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25157

Опубликовано: 14 авг. 2024
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*
Версия до 7.6.0 (исключая)

EPSS

Процентиль: 33%
0.00126
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-303
CWE-287

Связанные уязвимости

CVSS3: 6.5
github
больше 1 года назад

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

EPSS

Процентиль: 33%
0.00126
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-303
CWE-287