← Back

CVE-2024-25157

nvd nist
Published: Aug 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.2 / Impact: 5.2
Source: NVD

Description

An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.

Affected (1)

1 product
Goanywhere Managed File Transfer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.6.0

References (1)

Source: df4dee71-de3a-4139-9588-11b62fe6c0ff
Vendor Advisory

Timeline

No history available yet.