EUVD-2023-0644
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 10 Feb 2023. Evidence sources: cisa_kev.
- ENISA score
- 7.2 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
