Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application
ID: 2d5d2dfe-ecd1-502c-8a7b-573b85d25a84
STIX ID: report--2d5d2dfe-ecd1-502c-8a7b-573b85d25a84
Feed Name: The Hacker News
Threat Score
A critical SQL injection vulnerability (CVE-2024-5276, CVSS 9.8) affects Fortra FileCatalyst Workflow versions 5.1.6 build 135 and earlier, allowing attackers—potentially unauthenticated if anonymous access is enabled—to modify or delete application data and create administrative users; Tenable published a proof-of-concept and Fortra issued fixes in build 139 plus temporary servlet-disabling workarounds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
