PublicCVE

CVE-2024-0204

CRITICAL9.8
Public PoCHigh EPSS

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected products

Exploits & proofs of concept

Updated 15m ago · 2 sources