CVE-2024-11922 — Cross-site Scripting in Goanywhere Managed File Transfer
Severity
5.4MEDIUMNVD
EPSS
0.1%
top 65.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 28
Description
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-m6rq-x2h2-222p: Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7↗2025-04-28