CVE-2017-8760: XSS
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in courier/1000@/index.html with the authparams parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8760?
CVE-2017-8760 has a medium severity rating due to its potential exploitation leading to unauthorized access.
2
How do I fix CVE-2017-8760?
To fix CVE-2017-8760, upgrade your Accellion File Transfer Appliance to version FTA_9_12_180 or later.
3
What type of vulnerability is CVE-2017-8760?
CVE-2017-8760 is a Cross-Site Scripting (XSS) vulnerability.
4
What are the affected versions for CVE-2017-8760?
CVE-2017-8760 affects Accellion File Transfer Appliance versions prior to FTA_9_12_180.
5
Can CVE-2017-8760 be exploited remotely?
Yes, CVE-2017-8760 can potentially be exploited remotely by an attacker.