Impact
The vulnerability is a path traversal flaw in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT. It allows authenticated Web Users who possess Secure Folders and Secure Mail permissions to traverse out of their designated home directory and read any file on the system. This flaw can lead to disclosure of sensitive configuration data or credentials, compromising confidentiality.
Affected Systems
Affected systems are instances of Fortra GoAnywhere MFT earlier than version 7.10.2. The flaw exists on all deployments where the /attachRemoteFiles endpoint is exposed to Web Users with both Secure Folders and Secure Mail privileges. Only versions prior to the 7.10.2 release are vulnerable; all newer releases include the fix.
Risk and Exploitability
The CVSS score of 7.7 indicates moderate to high severity. With no EPSS data and absence from CISA KEV, the likelihood of exploitation is uncertain, but authenticated Web Users could exploit the flaw over the network. The attack requires valid credentials and specific permissions, so the attack surface is confined to users with both Secure Folders and Secure Mail access.
OpenCVE Enrichment