CVE-2021-46830

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/07/2022
Last modified:
29/09/2022

Description

A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:helpsystems:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* 6.8.3 (excluding)