ZeroHour

CVE-2024-25154

CVSS 3.1
5.3 medium
EPSS
<1%p39
Published
()
Modified
Description

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.

Vendors
fortra
Products
filecatalyst direct
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news