logo

Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released

ID: 9ce53323-beb2-5b6f-bb0f-7dc2fa711caf

STIX ID: report--9ce53323-beb2-5b6f-bb0f-7dc2fa711caf

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Fortra FileCatalyst Workflow has a critical SQL injection (CVE-2024-5276, CVSS 9.8) that can allow anonymous attackers (if anonymous access is enabled) to create admin users and manipulate the application database; Tenable published a PoC exploit and Fortra recommends upgrading to build 139 to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.