← back
CVE-2021-27101

CVE-2021-27101

CVSS 9.8 CRITICALEPSS 6.0%● KEV
In short

Accellion FTA versions 9.12.370 and earlier have a critical flaw that allows attackers to inject malicious SQL commands through specially crafted requests to a specific web page, potentially exposing or modifying sensitive data stored in the application's database.

Technical detail

SQL injection vulnerability in Accellion FTA ≤9.12.370 exploitable via malicious Host header in requests to document_root.html endpoint. Attack requires network access to the vulnerable application; successful exploitation enables arbitrary SQL query execution and potential unauthorized database access or modification.

Summary generated and translated by AI from the official description.
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →