accellion security advisories
5 threat alerts tracking vulnerabilities and security advisories that affect accellion products.
Vulnios monitors accellion CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent accellion security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2017-8790 — accellion — file_transfer_appliance
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
criticalCVE-2017-8790Critical Vulnerability: CVE-2017-8796 — accellion — file_transfer_appliance
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
criticalCVE-2017-8796Critical Vulnerability: CVE-2017-8794 — accellion — file_transfer_appliance
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.ht
criticalCVE-2017-8794Critical Vulnerability: CVE-2017-8303 — accellion — file_transfer_appliance
An issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in the method parameter.
criticalCVE-2017-8303Critical Vulnerability: CVE-2017-8789 — accellion — file_transfer_appliance
An issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.
criticalCVE-2017-8789
Track accellion exposure across your environment
Vulnios automatically cross-references your asset inventory against new accellion CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan