Security Advisory

CVE-2024-25155

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2024-03-13 14:15:54
Last updated 2024-08-01 23:36:21
Assigner Fortra
CVSS score 7.2
State PUBLISHED

Description

In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag.