CVE-2024-0204 is a critical authentication bypass vulnerability in Fortra GoAnywhere Managed File Transfer (MFT) affecting 6.x from 6.0.1 and 7.x prior to 7.4.1. The flaw allows a remote, unauthenticated attacker to create a new administrative user through the administration portal. Reported analysis attributes the issue to improper path normalization involving the initial account setup functionality, enabling direct access to the setup endpoint and bypass of intended authentication controls. This effectively exposes privileged administrative functionality to unauthenticated requests and can be used to establish attacker-controlled administrator access on vulnerable systems.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2024-0204.py) targeting Fortra GoAnywhere MFT versions prior to 7.4.1. The exploit leverages a critical authentication bypass vulnerability (CVE-2024-0204) that allows unauthenticated attackers to create a new administrator account by exploiting a path traversal flaw to access the initial account setup wizard. The script supports both single-target and multi-target (file-based) modes, uses multi-threading for efficiency, and provides colored output for clarity. The attacker supplies the desired admin username and password, and the script attempts two different path traversal payloads to maximize the chance of success. If successful, the attacker gains full administrative access to the target GoAnywhere MFT instance. The repository also includes a minimal README.md. No hardcoded IPs or domains are present; the script requires the attacker to specify the target URL(s). The main attack vector is network-based, exploiting HTTP endpoints exposed by the vulnerable application.
This repository contains a single Metasploit module targeting CVE-2024-0204, a critical unauthenticated remote code execution vulnerability in Fortra GoAnywhere MFT (versions 6.x from 6.0.1 and 7.x before 7.4.1, on both Linux and Windows). The exploit leverages an authentication bypass to create a new administrator account by abusing a path traversal vulnerability to access the InitialAccountSetup endpoint. After account creation, the module logs in as the new admin, uploads a JSP payload (such as a reverse shell), and triggers its execution via an HTTP request, resulting in RCE as the web server user. The module includes a check method to fingerprint the target version using an undocumented REST API endpoint. The exploit is operational, providing a working RCE chain, but is not fully weaponized (payloads are customizable via Metasploit). The repository is structured as a single Ruby file compatible with the Metasploit framework, and all logic is contained within this file.
This repository contains a Python exploit script (CVE-2024-0204.py) and a README.md. The exploit targets CVE-2024-0204, an authentication bypass vulnerability in Fortra GoAnywhere MFT. The script allows an attacker to create a new admin user on a vulnerable GoAnywhere MFT instance by sending crafted HTTP requests to the endpoint '/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml'. The script requires the attacker to provide the target endpoint URL, a desired username, and a password (minimum 8 characters). It first fetches the setup page to extract a required ViewState token, then submits a POST request to create the new admin user. If successful, the attacker gains full administrative access to the target system. The repository is straightforward, with the main exploit logic contained in a single Python file and usage instructions in the README.
This repository contains a Python exploit script (CVE-2024-0204.py) and a README.md. The exploit targets CVE-2024-0204, an authentication bypass vulnerability in Fortra GoAnywhere MFT. The script allows an attacker to create a new admin user on a vulnerable GoAnywhere MFT instance by sending crafted HTTP requests to the endpoint '/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml'. The script requires the attacker to specify the target endpoint URL, desired admin username, and password (with a minimum length of 8 characters). The README provides usage instructions and background information. The exploit is operational, providing a working method to gain administrative access to affected systems. No hardcoded credentials or payload customization is present; the attacker supplies the credentials at runtime. The main attack vector is network-based, exploiting a web-accessible endpoint.
This repository contains a proof-of-concept Python exploit for CVE-2024-0204, an authentication bypass vulnerability in Fortra GoAnywhere MFT. The main file, CVE-2024-0204.py, automates the process of exploiting a path traversal flaw to access the /wizard/InitialAccountSetup.xhtml endpoint, bypassing authentication controls. The script can target a single IP/URL or a list of targets, and for each, it attempts to create a new administrative user with randomly generated credentials. If successful, it prints the new admin username and password. The exploit works by sending crafted HTTP requests to the vulnerable endpoint, extracting necessary form tokens (ViewState), and submitting the admin creation form. The README provides background on the vulnerability, usage instructions, indicators of compromise (such as new admin users and log file locations), and mitigation advice. The repository is structured simply, with one exploit script and a detailed README. The exploit is network-based and targets the GoAnywhere MFT web interface.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical path traversal vulnerability in GoAnywhere MFT affecting Tomcat-based applications, for which a working exploit was developed by researchers.
Critical authentication bypass in GoAnywhere MFT enabling admin panel access and creation of unauthorized admin users; public weaponized exploits exist and exploitation attempts have been observed.
Critical authentication bypass vulnerability in Fortra GoAnywhere MFT caused by improper path normalization, allowing an unauthenticated attacker to create a new administrative user.
A critical authentication bypass in Fortra GoAnywhere MFT that allows an unauthenticated attacker to create an administrative user via the admin portal (forced browsing/direct request).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.