← Back

CVE-2024-11922

nvd nist
Published: Apr 28, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.

Affected (1)

1 product
Goanywhere Managed File Transfer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.8.0

References (1)

Source: df4dee71-de3a-4139-9588-11b62fe6c0ff
Vendor Advisory

Timeline

No history available yet.