Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Solution:
Workaround:
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://www.fortra.com/security/advisory/fi-2024-001 | vendor advisory |
https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml | permissions required |
http://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html | third party advisory vdb entry |
http://packetstormsecurity.com/files/176974/Fortra-GoAnywhere-MFT-Unauthenticated-Remote-Code-Execution.html |