Fortra GoAnywhere MFT is susceptible to remote code execution via unsafe deserialization of an arbitrary attacker-controlled object. This stems from a pre-authentication command injection vulnerability in the License Response Servlet.
id: CVE-2023-0669
info:
name: Fortra GoAnywhere MFT - Remote Code Execution
author: rootxharsh,
...