📦

fta

Vendor: accellion

Actively Exploited 4 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 2 Remote Access
Total CVEs 6 Total Indexed
Avg. EPSS 13.25% Exploit Prob.
Latest CVE CVE-2021-27730 Mar 02

Security Vulnerability Index

Page 1 / 1
9.8 CVSS

Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.

EPSS: 1.41%
6.1 CVSS

Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.

EPSS: 0.72%
9.8 CVSS

Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.

EPSS: 56.41%
9.8 CVSS

Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.

EPSS: 11.32%
7.8 CVSS

Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.

EPSS: 3.62%
9.8 CVSS

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

EPSS: 6.00%