PT-2021-2473 · Accellion · Accellion Fta
Published
2021-02-16
·
Updated
2026-03-08
·
CVE-2021-27101
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Accellion FTA versions 9 12 370 and earlier
Description
The issue is related to a lack of protection against SQL query structure exploitation. This can be exploited by a remote attacker to execute arbitrary SQL code and gain unauthorized access to protected information using a specially crafted request with a
Host header. The estimated number of potentially affected devices worldwide is not specified. Details about real-world incidents where this issue was exploited are not provided.Recommendations
For Accellion FTA versions 9 12 370 and earlier, update to version FTA 9 12 380 or later to resolve the issue. As a temporary workaround, consider restricting access to the
document root.html endpoint to minimize the risk of exploitation. Avoid using specially crafted Host headers in requests to this endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Accellion Fta