← back
CVE-2024-25153criticalCWE-472

Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

62Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 9.8epss 42%
from disclosure to weapon0 days
Published on NVDMar 13
1st PoCMar 12
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
In short

FileCatalyst Workflow allows attackers to upload files outside the intended folder through a specially crafted request, potentially enabling them to upload malicious web shells that execute arbitrary code on the server.

Technical detail

A directory traversal vulnerability in the 'ftpservlet' component accepts POST requests with path traversal sequences that bypass upload directory restrictions, allowing placement of JSP files in the web root where they are executed with application privileges, leading to remote code execution.

Summary generated and translated by AI from the official description.
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Fortra · FileCatalyst
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.