PT-2022-12936 · Unknown · Goanywhere Mft

Published

2022-07-27

·

Updated

2022-09-29

·

CVE-2021-46830

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoAnywhere MFT versions prior to 6.8.3
Description A path traversal issue exists that could allow an external user who self-registers with specific username and/or profile information to access files at a higher directory level than intended. This issue is related to the self-registration feature for the GoAnywhere Web Client.
Recommendations For versions prior to 6.8.3, update to version 6.8.3 or later to resolve the issue. As a temporary workaround, consider restricting self-registration or limiting access to sensitive files until the update is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-46830

Affected Products

Goanywhere Mft