CRITICAL
CVE-2021-27101
CVSS
9.8
KEV
Description
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
Summary dbcve.org
SQL injection vulnerability in Accellion File Transfer Appliance (FTA) allows remote, unauthenticated attackers to inject SQL commands via a crafted Host header in requests to the document_root.html endpoint. The vulnerability affects versions 9_12_370 and earlier.
Mitigation
Upgrade to FTA_9_12_380 or later to remediate this critical SQL injection vulnerability. If immediate patching is not feasible, restrict network access to the FTA admin interface and implement WAF rules to detect SQL injection patterns in HTTP headers.
EPSS Score
6%
Probability of exploitation in next 30 days
93.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.