CVE-2025-0049Information Exposure via Error Message in Goanywhere

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 62.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28

Description

When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

🔴Vulnerability Details

1
GHSA
GHSA-w7mr-p347-2rxr: When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute2025-04-28

📋Vendor Advisories

1
Microsoft
Out-of-bounds Read in vim/vim2023-01-10