cbcvebase.

Fortra Filecatalyst vulnerabilities

4 known vulnerabilities affecting fortra/filecatalyst.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2024-25153P2CRITICALCVSS 9.8≥ 5.1.4, < 5.1.62024-03-13
CVE-2024-25153 [CRITICAL] CWE-472 CVE-2024-25153: A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files t A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, includin
nvd
CVE-2025-8450P3HIGHCVSS 8.2≥ 5.1.6, ≤ 5.2.0 Build 802025-08-19
CVE-2025-8450 [HIGH] CWE-306 CVE-2025-8450: Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthentica Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
nvd
CVE-2024-25154P4MEDIUMCVSS 5.3≥ 3.8.6 , < 3.8.92024-03-13
CVE-2024-25154 [MEDIUM] CWE-22 CVE-2024-25154: Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.
nvd
CVE-2024-25155P4MEDIUMCVSS 6.1≥ 3.8.6 , < 3.8.92024-03-13
CVE-2024-25155 [MEDIUM] CWE-79 CVE-2024-25155: In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize il In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag.
nvd
Fortra Filecatalyst vulnerabilities | cvebase