← All CVEs

CVE-2024-5276

critical · 9.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data.  Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.

9.8
CVSS
90.1%
EPSS (exploit prob.)
100th
EPSS percentile
2024-06-25
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20CWE-89

Affected products

VendorProductAffected versions
fortrafilecatalyst_workflow< 5.1.6
fortrafilecatalyst_workflow5.1.6
fortrafilecatalyst_workflow5.1.6
fortrafilecatalyst_workflow5.1.6
fortrafilecatalyst_workflow5.1.6
fortrafilecatalyst_workflow5.1.6
fortrafilecatalyst_workflow5.1.6

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-5276