← Back to browse · API

CVE-2024-0204

Severity
CRITICAL
CVSS
9.8
EPSS
0.95086
Risk score
72.48
CISA KEV
No
PoC
No
Published
2024-01-22
Modified
2025-05-30
First seen
2026-08-07
Aliases
EUVD-2024-16003, GHSA-F8XF-39W2-MRC6
Products
Fortra:GoAnywhere MFT, Fortra:GoAnywhere MFT 6.0.1 <7.4.1
Sources
euvd EUVD-2024-16003

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

References