CVE-2021-27103
Description
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
Summary dbcve.org
Accellion FTA versions 9_12_411 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability in the wmProgressstat.html endpoint. Attackers can craft malicious POST requests to cause the FTA server to make arbitrary HTTP requests to internal or external resources, potentially exposing internal services, metadata endpoints, or enabling further reconnaissance and attacks.
Mitigation
Upgrade Accellion FTA to version FTA_9_12_416 or later to remediate this vulnerability. If immediate upgrading is not possible, implement network segmentation to restrict the FTA server's ability to connect to sensitive internal resources.