← Back to CVE List

CVE-2024-25153

Published: 2024-03-13T15:15Z
Last Modified: 2025-01-21T19:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt