CVE-2024-0204

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
22/01/2024
Last modified:
02/02/2024

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* 7.0.0 (including) 7.4.1 (excluding)
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:6.0.0:*:*:*:*:*:*:*