Description
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping.
This issue affects GoAnywhere: before 7.8.0.
Published: 2025-04-28
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to GoAnywhere 7.8.0 or later.


Vendor Workaround

This issue occurs when the Web User does not have Create permission on Subfolders. It is a bug that happens when a user tries to upload a file to a directory that doesn’t exist yet (If they have permissions to create sub directories, then the non-existent directory would be created automatically). Note: This workaround requires supplying an additional permission that the Web User does not have in vulnerable configurations.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-14216 When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
History

Sat, 10 May 2025 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Fortra
Fortra goanywhere Managed File Transfer
CPEs cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*
Vendors & Products Fortra
Fortra goanywhere Managed File Transfer

Mon, 28 Apr 2025 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
Description When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
Title Disclosure of sensitive information in an error message in GoAnywhere prior to version 7.8.0
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Fortra Goanywhere Managed File Transfer
cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2025-04-28T22:28:10.671Z

Reserved: 2024-11-27T18:20:36.029Z

Link: CVE-2025-0049

cve-icon Vulnrichment

Updated: 2025-04-28T22:28:06.993Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-28T21:15:56.703

Modified: 2025-05-10T00:55:19.180

Link: CVE-2025-0049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses