PT-2016-5127 · Accellion · Accellion File Transfer Appliance
Orange Tsai
·
Published
2016-05-07
·
Updated
2016-05-10
·
CVE-2016-2350
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Accellion File Transfer Appliance (FTA) versions prior to FTA 9 12 40
Description
The issue concerns multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. This can be achieved via unspecified input to the following API endpoints: "getimageajax.php", "move partition frame.html", or "wmInfo.html".
Recommendations
For Accellion File Transfer Appliance (FTA) versions prior to FTA 9 12 40, update to version FTA 9 12 40 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoints until a patch is applied. Avoid using unspecified input to these endpoints to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accellion File Transfer Appliance