Description
A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.
Published: 2024-08-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to FileCatalyst Workflow 5.1.7 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-47691 A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.
History

Tue, 27 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra filecatalyst Workflow
CPEs cpe:2.3:a:fortra:filecatalyst_workflow:*:*:*:*:*:*:*:*
Vendors & Products Fortra
Fortra filecatalyst Workflow
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can lead to a loss of confidentiality, integrity, and availability.
Title SQL Injection in FileCatalyst Workflow 5.1.6 Build 139 (and earlier)
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fortra Filecatalyst Workflow
cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2024-08-29T03:55:31.502Z

Reserved: 2024-07-09T20:01:49.676Z

Link: CVE-2024-6632

cve-icon Vulnrichment

Updated: 2024-08-27T14:57:29.508Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-27T15:15:17.300

Modified: 2024-08-30T14:07:18.443

Link: CVE-2024-6632

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses