PT-2017-18533 · Accellion · Accellion Fta
Paulos Yibelo
·
Published
2017-05-05
·
Updated
2019-10-03
·
CVE-2017-8793
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Accellion FTA versions prior to FTA 9 12 180
Description
An issue allows an attacker to bypass the Same Origin Policy by sending a POST request to the "home/seos/courier/web/wmProgressstat.html.php" endpoint with an attacker domain in the
acallow parameter, resulting in the device responding with an Access-Control-Allow-Origin header that grants site access to the attacker.Recommendations
For Accellion FTA versions prior to FTA 9 12 180, update to version FTA 9 12 180 or later to resolve the issue. As a temporary workaround, consider restricting access to the "home/seos/courier/web/wmProgressstat.html.php" endpoint to minimize the risk of exploitation. Avoid using the
acallow parameter in this endpoint until the issue is resolved.Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accellion Fta