CVE-2024-11922Cross-site Scripting in Goanywhere Managed File Transfer

Severity
5.4MEDIUMNVD
EPSS
0.1%
top 65.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28

Description

Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-m6rq-x2h2-222p: Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 72025-04-28