Executive brief
Accellion FTA contains a server-side request forgery (SSRF) vulnerability that can be triggered via a crafted POST request to wmProgressstat.html. This vulnerability has been observed being exploited in the wild.
Affected products
- Accellion FTA 9_12_411 and earlier
Timeline
- 2021-02-16: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-17: patched: Due date for remediation per CISA KEV catalog; fixed in FTA_9_12_416