CVE-2024-11922
Last modified
CVE-2024-11922 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert arbitrary HTML or JavaScript into an email.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortra | Goanywhere Managed File Transfer | < 7.8.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-11922?
How severe is CVE-2024-11922?
How do I fix CVE-2024-11922?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-11917The JobSearch WP Job Board plugin for WordPress is vulnerabl…8.1
- CVE-2024-11918The Image Alt Text plugin for WordPress is vulnerable to una…4.3
- CVE-2024-11919Inappropriate implementation in Intents in Google Chrome on …4.3
- CVE-2024-1192A vulnerability was found in South River WebDrive 18.00.5057…5.5
- CVE-2024-11920Inappropriate implementation in Dawn in Google Chrome on Mac…4.3
- CVE-2024-11921The GiveWP WordPress plugin before 3.19.0 does not sanitise…4.8
- CVE-2024-11923Under certain log settings the IAM or CORE service will log …5.5
- CVE-2024-11924The Icegram Express formerly known as Email Subscribers Wor…3.5
- CVE-2024-11925The JobSearch WP Job Board plugin for WordPress is vulnerabl…9.8
- CVE-2024-11926The Travel Booking WordPress Theme theme for WordPress is vu…6.5
- CVE-2024-11928The iChart – Easy Charts and Graphs plugin for WordPress is …6.4
- CVE-2024-11929The Responsive FlipBook Plugin Wordpress plugin for WordPres…6.4
Are you affected by CVE-2024-11922?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
