CVE-2021-27101
CVE-2021-27101
In short
Accellion FTA versions 9.12.370 and earlier have a critical flaw that allows attackers to inject malicious SQL commands through specially crafted requests to a specific web page, potentially exposing or modifying sensitive data stored in the application's database.
Technical detail
SQL injection vulnerability in Accellion FTA ≤9.12.370 exploitable via malicious Host header in requests to document_root.html endpoint. Attack requires network access to the vulnerable application; successful exploitation enables arbitrary SQL query execution and potential unauthorized database access or modification.
Summary generated and translated by AI from the official description.
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →