PT-2024-4324 · Fortra · Filecatalyst Workflow
Tenable Research
·
Published
2024-06-25
·
Updated
2025-04-05
·
CVE-2024-5276
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Fortra FileCatalyst Workflow versions 5.1.6 Build 135 and earlier
Description
The issue is related to a SQL injection vulnerability that allows an attacker to modify application data. This can likely result in the creation of administrative users and the deletion or modification of data in the application database. However, data exfiltration via SQL injection is not possible using this vulnerability. Successful exploitation requires either a Workflow system with anonymous access enabled for unauthenticated attackers or an authenticated user.
Recommendations
For versions 5.1.6 Build 135 and earlier, update to a version that includes the fix for this SQL injection vulnerability.
As a temporary workaround, consider disabling anonymous access in the Workflow system to minimize the risk of unauthenticated exploitation.
Restrict access to the application database to prevent potential data modification or deletion.
Avoid using the application until the issue is resolved to prevent potential privilege escalation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Filecatalyst Workflow