Executive brief
Accellion FTA is vulnerable to SQL injection via a crafted Host header in requests to document_root.html. This allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to full system compromise.
Affected products
- Accellion FTA 9_12_370 and earlier
Timeline
- 2021-02-16: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: NVD advisory published/updated