PT-2017-18533 · Accellion · Accellion Fta

Paulos Yibelo

·

Published

2017-05-05

·

Updated

2019-10-03

·

CVE-2017-8793

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Accellion FTA versions prior to FTA 9 12 180
Description An issue allows an attacker to bypass the Same Origin Policy by sending a POST request to the "home/seos/courier/web/wmProgressstat.html.php" endpoint with an attacker domain in the acallow parameter, resulting in the device responding with an Access-Control-Allow-Origin header that grants site access to the attacker.
Recommendations For Accellion FTA versions prior to FTA 9 12 180, update to version FTA 9 12 180 or later to resolve the issue. As a temporary workaround, consider restricting access to the "home/seos/courier/web/wmProgressstat.html.php" endpoint to minimize the risk of exploitation. Avoid using the acallow parameter in this endpoint until the issue is resolved.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8793

Affected Products

Accellion Fta