CVE-2021-46830: Path Traversal
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-46830.
What software is affected by this vulnerability?
GoAnywhere MFT before 6.8.3 is affected by this vulnerability.
What is the severity of CVE-2021-46830?
CVE-2021-46830 has a severity rating of medium (6.5).
How does this vulnerability work?
This vulnerability allows an external user who self-registers with a specific username and/or profile information to gain unauthorized access to files at a higher level.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to upgrade to GoAnywhere MFT version 6.8.3 or later.