When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping.
This issue affects GoAnywhere: before 7.8.0.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0. | |
Title | Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0 | |
Weaknesses | CWE-209 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Fortra
Published: 2025-04-28T20:55:06.256Z
Updated: 2025-04-28T22:28:10.671Z
Reserved: 2024-11-27T18:20:36.029Z
Link: CVE-2025-0049

Updated: 2025-04-28T22:28:06.993Z

Status : Awaiting Analysis
Published: 2025-04-28T21:15:56.703
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-0049

No data.