CRITICAL

CVE-2021-27101

Accellion Fta 2021-02-16 CVSS v3.1
CVSS
9.8
KEV

Description

Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.

Summary dbcve.org

SQL injection vulnerability in Accellion File Transfer Appliance (FTA) allows remote, unauthenticated attackers to inject SQL commands via a crafted Host header in requests to the document_root.html endpoint. The vulnerability affects versions 9_12_370 and earlier.

Mitigation

Upgrade to FTA_9_12_380 or later to remediate this critical SQL injection vulnerability. If immediate patching is not feasible, restrict network access to the FTA admin interface and implement WAF rules to detect SQL injection patterns in HTTP headers.

EPSS Score

6%
Probability of exploitation in next 30 days
93.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE