CVE-2024-25155: Fortra Filecatalyst Direct
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in a URL which is then displayed on a subsequent error page. A malicious actor could craft a URL which would then execute arbitrary code within an HTML script tag.
Affected products
- Fortra Filecatalyst Direct: from 3.0.0, before 3.8.9 (fixed in 3.8.9)
Published 2024-03-13. Last modified 2026-06-17.