ID:11424 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

 
Main Vulnerability Database Exploits ID:11424 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

ID:11424 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

Published: May 30, 2025


Vulnerability identifier: #VU85739
Vulnerability risk: Critical
CVE-ID: CVE-2024-0204
CWE-ID: CWE-862
Exploitation vector: Remote access
Vulnerable software:
GoAnywhere MFT

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization checks related to the InitialAccountSetup.xhtml file along with a path normalization issue. A remote non-authenticated attacker can bypass authentication process and gain full control over the system by creating an administrative account.

Exploit example to access the initial setup page bypassing the authorization check:

https://[host]:8001/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml


Remediation

Install updates from vendor's website.