Vulnerabilities > CVE-2017-8794 - Server-Side Request Forgery (SSRF) vulnerability in Accellion File Transfer Appliance 80540
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
NONE Summary
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |