// For flags

CVE-2024-25153

Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.

Un directory traversal dentro del 'ftpservlet' de FileCatalyst Workflow Web Portal permite cargar archivos fuera del directorio 'uploadtemp' previsto con una solicitud POST especialmente manipulada. En situaciones en las que un archivo se carga correctamente en DocumentRoot del portal web, se pueden utilizar archivos JSP especialmente manipulados para ejecutar código, incluidos los shells web.

*Credits: Tom Wedgbury, LRQA Nettitude
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
Yes
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-02-06 CVE Reserved
  • 2024-03-13 CVE Published
  • 2024-03-13 First Exploit
  • 2024-03-14 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-472: External Control of Assumed-Immutable Web Parameter
CAPEC
  • CAPEC-650: Upload a Web Shell to a Web Server
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Fortra
Search vendor "Fortra"
FileCatalyst
Search vendor "Fortra" for product "FileCatalyst"
>= 5.1.4 < 5.1.6
Search vendor "Fortra" for product "FileCatalyst" and version " >= 5.1.4 < 5.1.6"
en
Affected