The Fortra FileCatalyst Workflow platform is vulnerable to an SQL injection vulnerability , which could allow remote, unauthorized attackers to create fake admin users and manipulate data in the application database .

FileCatalyst Workflow is a file exchange and sharing platform that supports large file sizes. It is used by organizations around the world.
The critical vulnerability (CVSS v3.1:9.8), which is tracked as CVE-2024-5276, was discovered on May 15, 2024 by researchers at Tenable.
See also: Apple fixes AirPods Bluetooth vulnerability
Fortra explains that the vulnerability allows for the creation of an admin user and manipulation of the database ( deleting or modifying data), but data theft is not possible.
The vulnerability affects FileCatalyst Workflow 5.1.6 Build 135 and earlier. Fixes were made available in FileCatalyst Workflow 5.1.6 build 139.
Unauthorized exploitation requires anonymous access on the target. Otherwise, authentication is required to exploit CVE-2024-5276.
See also: Botnet exploits vulnerability in Zyxel NAS devices

Fortra FileCatalyst Workflow: An exploit is available
Tenable discovered the CVE-2024-5276 vulnerability on May 15, 2024, and first disclosed the issue to Fortra on May 22, along with a PoC exploit.
At the same time as publishing the Fortra security bulletin , Tenable published the exploit, showing how the vulnerability can be used
There have been no reports of active exploitation of the vulnerability, but the release of a working exploit helps cybercriminals.
See also: GrimResource: New attack uses MSC files and Windows XSS vulnerability
It is important for developers to understand the risks of SQL injection vulnerabilities and take the necessary precautions to prevent them. Regular security testing and timely software updates are crucial to maintaining a secure environment and protecting sensitive data from malicious attacks. By implementing appropriate practices and staying informed about potential threats, developers can ensure the protection and integrity of applications . With a combination of preventive measures and awareness , we can mitigate the risk and maintain a safe digital landscape for everyone.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
