QID 731260
Date Published: 2024-03-18
QID 731260: Fortra FileCatalyst WorkFlow Remote Code Execution (RCE) Vulnerability (Intrusive Check)
A critical security vulnerability, designated as CVE-2024-25153, has been identified in Fortra FileCatalyst Workflow. This vulnerability allows remote attackers to execute arbitrary code on the targeted web server without requiring authentication. Specifically, the vulnerability enables an attacker to upload malicious files to the server and traverse directories, leading to Remote Code Execution (RCE).
Affected Versions:
Fortra FileCatalyst Workflow 5.x versions prior to 5.1.6 Build 114.
Note: A Fortra FileCatalyst WorkFlow instance is only exploitable if an anonymous user has access to upload files.
QID Detection Logic (Unauthenticated):
This is an intrusive detection. This QID tries to upload a static JSP file '731260.jsp' containing a static text 'File Generated By QID 731260', as an anonymous user. The '731260.jsp' file can be accessed by sending a HTTP GET request to the '/workflow/qualystest/731260.jsp' endpoint. A target is flagged as vulnerable if Qualys Scanner is able to upload 731260.jsp file to the FileCatalyst WorkFlow server. Please note that this QID does not check the version of FileCatalyst WorkFlow running on the target.
Exploitation of this vulnerability may allow an unauthenticated remote attacker to upload malicious JSP files to the server, leading to arbitrary code execution and complete system compromise.
- Fortra Security Advisory (FI-2024-002) -
www.fortra.com/security/advisory/fi-2024-002
CVEs related to QID 731260
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| FI-2024-002 |
|