Vulnerability record · CVE-2024-5276 · published 25 June 2024
CVE-2024-5276: Fortra FileCatalyst Workflow SQL injection allows data modification
Fortra · Filecatalyst Workflow
Fortra FileCatalyst Workflow contains a SQL injection flaw (CWE-89, improper input validation) that lets an attacker modify application data, including creating administrative users and deleting or altering database records. Data exfiltration via the injection is not possible. The issue affects all versions from 5.1.6 Build 135 and earlier.
Description
A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion or modification of data in the application database. Data exfiltration via SQL injection is not possible using this vulnerability. Successful unauthenticated exploitation requires a Workflow system with anonymous access enabled, otherwise an authenticated user is required. This issue affects all versions of FileCatalyst Workflow from 5.1.6 Build 135 and earlier.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 with network reachability, no privileges or user interaction required, high EPSS, and a public exploit reference, though KEV listing is absent.
What it is
Fortra FileCatalyst Workflow contains a SQL injection flaw (CWE-89, improper input validation) that lets an attacker modify application data, including creating administrative users and deleting or altering database records. Data exfiltration via the injection is not possible. The issue affects all versions from 5.1.6 Build 135 and earlier.
Impact
An attacker can create administrative accounts and delete or modify data in the application database, leading to full application compromise and integrity loss. Confidentiality is not impacted per the CVSS vector.
Attack surface
Reachable over the network with no authentication and no user interaction when anonymous access is enabled on the Workflow system; otherwise an authenticated user is required. The CVSS vector is AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high (0.90067, 99.788th percentile) and a third-party advisory is tagged Exploit, indicating public exploit information exists.
What to do
- Apply the vendor fix or mitigation from Fortra advisory FI-2024-008 and the FileCatalyst Workflow KB article; upgrade beyond 5.1.6 Build 135.
- Disable anonymous access on FileCatalyst Workflow systems where it is not strictly required.
- Restrict network exposure of the Workflow interface to trusted networks or place it behind a VPN or reverse proxy with access controls.
- Enforce least privilege on the database account used by FileCatalyst Workflow to limit the scope of data modification.
- Audit existing administrative accounts and database records for unauthorized changes.
Detection
- Monitor Workflow and database logs for SQL syntax anomalies, unexpected query errors, or injection-like payloads in request parameters.
- Alert on creation of new administrative users or privilege changes in FileCatalyst Workflow.
- Baseline and monitor for unusual bulk deletions or modifications in the application database.
- Review access logs for unauthenticated requests to Workflow endpoints when anonymous access is enabled.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability | MitigationVendor Advisory |
| https://www.fortra.com/security/advisory/fi-2024-008 | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2024-25 | ExploitThird Party Advisory |
| https://support.fortra.com/filecatalyst/kb-articles/advisory-6-24-2024-filecatalyst-workflow-sql-injection-vulnerability | MitigationVendor Advisory |
| https://www.fortra.com/security/advisory/fi-2024-008 | Vendor Advisory |
| https://www.tenable.com/security/research/tra-2024-25 | ExploitThird Party Advisory |
Track CVE-2024-5276 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-5276), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.