CVE-2025-0049
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Apr 28, 2025
Updated: May 10, 2025
CWE ID 209
Summary
CVE-2025-0049 is a vulnerability affecting GoAnywhere MFT Manager. When users without create permissions attempt to upload files to non-existent directories, the server responds with an error message containing the absolute server path. This potentially exposes application mapping information, allowing for fuzzing attacks. GoAnywhere versions prior to 7.8.0 are affected by this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Fortra