Filtered by vendor Fortra
Subscriptions
Filtered by product Filecatalyst
Subscriptions
Total
1 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-25153 | 1 Fortra | 2 Filecatalyst, Filecatalyst Workflow | 2025-09-19 | 9.8 Critical |
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells. |
Page 1 of 1.