fortra filecatalyst_direct CVE Vulnerabilities (2)

CVEs: 2 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting fortra filecatalyst_direct (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 12 of 2 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-25155 In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag.  df4dee71-de3a-4139-9588-11b62fe6c0ff 7.2 1.04% 2024-03-13 2025-01-21
CVE-2024-25154 Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to return files located outside of the web root which may lead to data leakage.   df4dee71-de3a-4139-9588-11b62fe6c0ff 5.3 0.29% 2024-03-13 2025-01-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence