CVE-2017-8792: XSS
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/useradd.html with the param parameter.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8792?
CVE-2017-8792 is considered a medium severity vulnerability due to its potential for cross-site scripting (XSS).
2
How do I fix CVE-2017-8792?
To fix CVE-2017-8792, upgrade your Accellion FTA device to version FTA_9_12_180 or later.
3
What kind of vulnerability is CVE-2017-8792?
CVE-2017-8792 is a cross-site scripting (XSS) vulnerability affecting the Accellion File Transfer Appliance.
4
Which versions of Accellion File Transfer Appliance are affected by CVE-2017-8792?
CVE-2017-8792 affects Accellion File Transfer Appliance versions before FTA_9_12_180.
5
What is the attack vector for CVE-2017-8792?
The attack vector for CVE-2017-8792 is through the manipulation of the param parameter in the user_add.html page.