216.73.216.233

CVE-2024-5276

· Published 25/06/2024 20:15 · Modified 25/06/2024 20:15

Labels: CVE-2024-5276 2024-06-25CVE-2024-5276CWE-20df4dee71-de3a-4139-9588-11b62fe6c0ff

Essential information

Published
25/06/2024 20:15
Modified
25/06/2024 20:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
df4dee71-de3a-4139-9588-11b62fe6c0ff
NVD
View on NVD

References