Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool

Details of a significant security vulnerability that has been fixed in Fortra’s FileCatalyst file transfer software have been made public. This vulnerability might give unauthenticated attackers access to remote code execution on vulnerable servers.

The vulnerability, identified as CVE-2024-25153, has a CVSS score of 9.8 out of a possible 10.

Using a specifically constructed POST request, files can be uploaded outside of the intended ‘uploadtemp’ directory using a directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal, the business stated in an alert last week.

When a file is successfully uploaded to the DocumentRoot of a web portal, specifically designed JSP files may be used to run programs read more Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *