CVE-2017-8304: XSS
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8304?
CVE-2017-8304 is classified as a high severity XSS vulnerability.
2
How do I fix CVE-2017-8304?
To fix CVE-2017-8304, upgrade to Accellion FTA version 9_12_180 or later.
3
What software is affected by CVE-2017-8304?
CVE-2017-8304 affects Accellion File Transfer Appliance devices prior to version 9_12_180.
4
What kind of attack is possible with CVE-2017-8304?
CVE-2017-8304 allows an attacker to execute cross-site scripting (XSS) through a crafted URI.
5
Can CVE-2017-8304 be exploited remotely?
Yes, CVE-2017-8304 can be exploited remotely by an attacker with knowledge of the vulnerable URI.