CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.5. See the original NVD description below for full technical details.
CVE
CVE-2025-0049
Severity
LOW
CVSS
3.5
EPSS
0.25%
Original NVD Description
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere: before 7.8.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)