CVE-2025-8148
EUVD-2025-20149505.12.2025, 21:15
An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| fortra | goanywhere_managed_file_transfer | 𝑥 < 7.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration