Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-0204Forced Browsing in Goanywhere MFT

Severity
9.8CRITICALNVD
VulnCheck7.2
EPSS
93.0%
top 0.21%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 22
Latest updateMay 29

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5fortra/goanywhere_mft6.0.17.4.1

🔴Vulnerability Details

4
GHSA
GHSA-f8xf-39w2-mrc6: Authentication bypass in Fortra's GoAnywhere MFT prior to 72024-01-22
VulnCheck
Fortra GoAnywhere MFT Direct Request ('Forced Browsing')2024
VulnCheck
Progress MOVEit Transfer SQL Injection Vulnerability2023
VulnCheck
Fortra GoAnywhere MFT Remote Code Execution Vulnerability2023

💥Exploits & PoCs

3
Exploit-DB
Fortra GoAnywhere MFT 7.4.1 - Authentication Bypass2025-05-29
Metasploit
Fortra GoAnywhere MFT Unauthenticated Remote Code Execution
Nuclei
Fortra GoAnywhere MFT - Authentication Bypass

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS GoAnywhere MFT Authentication Bypass Attempt - POST Request M1 (CVE-2024-0204)2024-01-24
Suricata
ET WEB_SPECIFIC_APPS GoAnywhere MFT Authentication Bypass Attempt - GET Request M1 (CVE-2024-0204)2024-01-24

📋Vendor Advisories

1
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2024-02042024-03-11

🕵️Threat Intelligence

7
Securelist
Advanced threat predictions for 20252024-11-25
Securelist
Advanced threat predictions for 20252024-11-25
Tenable
Cybersecurity Snapshot: LockBit Gang Gets Knocked Down, as CISA Stresses Security of Water Plants2024-02-23
Wiz
Crying Out Cloud - February Newsletter | Wiz2024-02-01
Bleepingcomputer
Fortra warns of new critical GoAnywhere MFT auth bypass, patch now2024-01-23