Vulnerabilities > Fortra

DATE CVE VULNERABILITY TITLE RISK
2024-01-22 CVE-2024-0204 Forced Browsing vulnerability in Fortra Goanywhere Managed File Transfer
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
network
low complexity
fortra CWE-425
critical
9.8
2023-11-22 CVE-2023-6253 Insecure Storage of Sensitive Information vulnerability in Fortra Digital Guardian Agent
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
local
low complexity
fortra CWE-922
6.0
2023-09-19 CVE-2021-26837 SQL Injection vulnerability in Fortra Delivernow
SQL Injection vulnerability in SearchTextBox parameter in Fortra (Formerly HelpSystems) DeliverNow before version 1.2.18, allows attackers to execute arbitrary code, escalate privileges, and gain sensitive information.
network
low complexity
fortra CWE-89
critical
9.8
2023-02-06 CVE-2023-0669 Deserialization of Untrusted Data vulnerability in Fortra Goanywhere Managed File Transfer
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
network
low complexity
fortra CWE-502
7.2