First published: Fri May 05 2017(Updated: )
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/smtpg_add.html with the param parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Secure File Transfer Appliance | <=9_12_40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8795 is classified as a medium severity vulnerability due to its potential for exploitation via XSS.
To fix CVE-2017-8795, update your Accellion FTA devices to at least version FTA_9_12_180 or higher.
CVE-2017-8795 is a cross-site scripting (XSS) vulnerability found in the smtpg_add.html page.
CVE-2017-8795 affects Accellion Secure File Transfer Appliances running versions prior to FTA_9_12_180.
Exploiting CVE-2017-8795 could allow an attacker to execute arbitrary scripts in the context of the user’s session.