📦

filecatalyst_direct

Vendor: fortra

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 0.42% Exploit Prob.
Latest CVE CVE-2024-25155 Mar 13

Security Vulnerability Index

Page 1 / 1
7.2 CVSS

In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag. 

EPSS: 0.38%
5.3 CVSS

Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.  

EPSS: 0.46%