CVE-2026-0972
Eine HTML-Injektion ist in den von dem System generierten E-Mails von Fortras GoAnywhere MFT vor Version 7.10.0 möglich. Hinweis: Der Ti… (CVE-2026-0972)
mediumEPSS 0.1 %
Beschreibung
Metriken
Severity
medium
53.31
kein öffentlicher PoC bekannt
5.4
Veröffentlicht
2026-04-21 14:14 UTC
CWE-74
Weakness-Klassen (CWE)
CWE-74Class
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
cwe.mitre.org →
Quellen & Referenzen
IDCVE-2026-0972