ID:9526 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

 
Main Vulnerability Database Exploits ID:9526 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

ID:9526 - Exploit for Missing Authorization in GoAnywhere MFT - CVE-2024-0204

Published: January 26, 2024


Vulnerability identifier: #VU85739
Vulnerability risk: Critical
CVE-ID: CVE-2024-0204
CWE-ID: CWE-862
Exploitation vector: Remote access
Vulnerable software:
GoAnywhere MFT

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to missing authorization checks related to the InitialAccountSetup.xhtml file along with a path normalization issue. A remote non-authenticated attacker can bypass authentication process and gain full control over the system by creating an administrative account.

Exploit example to access the initial setup page bypassing the authorization check:

https://[host]:8001/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml


Remediation

Install updates from vendor's website.