Junglewise Threat Intelligence

CVE-2021-27101: Accellion FTA SQL Injection Vulnerability

CVE-2021-27101 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Accellion FTA. Vendors: Accellion.

Executive brief

Accellion FTA is vulnerable to SQL injection via a crafted Host header in requests to document_root.html. This allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to full system compromise.

Affected products

  • Accellion FTA 9_12_370 and earlier

Timeline

  • 2021-02-16: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: NVD advisory published/updated

Related threats