QID 731096
Date Published: 2024-01-23
QID 731096: GoAnywhere Managed File Transfer (MFT) Authentication Bypass Vulnerability
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
Affected Versions:
All versions of GoAnywhere MFT prior to version 7.4.1
QID Detection Logic (Unauhtenticated):
This QID checks for vulnerable GoAnywhere MFT target by sending a GET request to the '/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml' endpoint and checks if the Account Setup page is accessible.
Successful exploitation of the vulnerability may allow a remote unauthenticated user create an admin user via the administration portal, leading to complete system compromise.
Solution
Customers are advised to upgrade to GoAnywhere Managed File Transfer (MFT) 7.4.1 or later. For more information, please refer to FI-2024-001
Vendor References
- GoAnywhere MFT Security Advisory -
www.fortra.com/security/advisory/fi-2024-001
CVEs related to QID 731096
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| fi-2024-001 |
|