Vulnerabilities > Fortra > Goanywhere Managed File Transfer > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-14 CVE-2024-25157 Improper Authentication vulnerability in Fortra Goanywhere Managed File Transfer
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages.
network
low complexity
fortra CWE-287
6.5
2024-03-14 CVE-2024-25156 Path Traversal vulnerability in Fortra Goanywhere Managed File Transfer
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
network
low complexity
fortra CWE-22
6.5