Fortra GoAnywhere MFT
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*
- < 7.8.0
A cross-site scripting vulnerability has been identified in Fortra's GoAnywhere Web Client, in versions prior to 7.8.0. This issue arises from missing input validation in certain features, allowing an attacker with permission to send emails to inject arbitrary HTML or JavaScript into the message. The vulnerability is particularly concerning for emails that do not use Secure Mail.
Exploitation of this vulnerability could lead to cross-site scripting attacks, where injected scripts are executed in the context of the user's browser.
Users can upgrade to GoAnywhere MFT version 7.8.0 or later to address this vulnerability. It is also recommended to limit access to only trustworthy Web Users.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.