Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released
ID: 9ce53323-beb2-5b6f-bb0f-7dc2fa711caf
STIX ID: report--9ce53323-beb2-5b6f-bb0f-7dc2fa711caf
Feed Name: Bleeping Computer
Threat Score
Fortra FileCatalyst Workflow has a critical SQL injection (CVE-2024-5276, CVSS 9.8) that can allow anonymous attackers (if anonymous access is enabled) to create admin users and manipulate the application database; Tenable published a PoC exploit and Fortra recommends upgrading to build 139 to remediate the issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
