Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2024-25153 Details
Description
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 12, 2024Exploitation: PocAutomatable: YesTechnical Impact: Total
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nettitude/CVE-2024-25153/blob/master/CVE-2024-25153.py | CISA-ADP | |
| https://filecatalyst.software/public/filecatalyst/Workflow/5.1.6.114/fcweb_releasenotes.html | CVE | Release Notes |
| https://www.fortra.com/security/advisory/fi-2024-002 | CVE | Vendor Advisory |
| https://filecatalyst.software/public/filecatalyst/Workflow/5.1.6.114/fcweb_releasenotes.html | Fortra | Release Notes |
| https://www.fortra.com/security/advisory/fi-2024-002 | Fortra | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
| CWE-472 | External Control of Assumed-Immutable Web Parameter | Fortra |
Affected Products
| Product | Versions |
|---|---|
| fortra filecatalyst workflow | >= 5.0, < 5.1.6 5.1.6 build112 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | Fortra |
| Sep 19, 2025 | CVE Modified | CISA-ADP |
| Jan 21, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | Fortra |
| Mar 13, 2024 | New CVE Received | Fortra |