Fortra GoAnywhere MFT
cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*
- < 7.10.0
A vulnerability in Fortra's GoAnywhere MFT, prior to version 7.10.0, allows attackers to manipulate HTTP headers to initiate a DNS lookup. This issue also facilitates DNS rebinding attacks and could lead to unauthorized information disclosure.
Exploitation of this vulnerability could result in DNS lookups being triggered by the application, potentially allowing for DNS rebinding attacks, which could be used to bypass the same-origin policy in web browsers. Additionally, the vulnerability could lead to unauthorized information disclosure.
Users are advised to update to Fortra GoAnywhere MFT version 7.10.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.