logo

Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application

ID: 2d5d2dfe-ecd1-502c-8a7b-573b85d25a84

STIX ID: report--2d5d2dfe-ecd1-502c-8a7b-573b85d25a84

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-27

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

A critical SQL injection vulnerability (CVE-2024-5276, CVSS 9.8) affects Fortra FileCatalyst Workflow versions 5.1.6 build 135 and earlier, allowing attackers—potentially unauthenticated if anonymous access is enabled—to modify or delete application data and create administrative users; Tenable published a proof-of-concept and Fortra issued fixes in build 139 plus temporary servlet-disabling workarounds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.