CVE-2025-8450: Unrestricted File Upload in FileCatalyst
Published Aug 19, 2025
·Updated
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
Affected Software
1 affected component
Fortra FileCatalyst
Remediation
Information
Update to the latest version of FileCatalyst, Version 5.2.0 - Build 130
Event History
Aug 19, 2025
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Jul 24, 57619
Event
via FIRST·05:41 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-8450?
CVE-2025-8450 is classified as a high severity vulnerability due to its potential for unauthorized file uploads.
2
How do I fix CVE-2025-8450?
To fix CVE-2025-8450, implement proper access controls to restrict file upload capabilities to authenticated users only.
3
Who is affected by CVE-2025-8450?
CVE-2025-8450 affects users of Fortra's FileCatalyst workflow component that do not have proper access control mechanisms in place.
4
What types of files can be uploaded due to CVE-2025-8450?
Due to CVE-2025-8450, unauthenticated users can upload arbitrary files, which could potentially include harmful files.
5
Is there a patch available for CVE-2025-8450?
As of now, check with Fortra for any available patches or updates that address CVE-2025-8450.