SQL Injection Vulnerability in FileCatalyst Workflow
CVE-2024-6632

7.2HIGH

Key Information:

Vendor
Fortra
Vendor
CVE Published:
27 August 2024

Summary

A vulnerability in FileCatalyst Workflow developed by Fortra allows super administrators to exploit a particular field to execute SQL injection attacks. This manipulation can compromise sensitive data, leading to potential breaches in confidentiality, integrity, and availability of information. Such vulnerabilities highlight the importance of securing admin-level access and ensuring that robust security measures are in place to protect against unauthorized database access.

Affected Version(s)

FileCatalyst Workflow 5.0.4 <= 5.1.6 Build 139

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dynatrace Security Research
.