CVE-2017-8795: XSS
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/smtpgadd.html with the param parameter.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8795?
CVE-2017-8795 is classified as a medium severity vulnerability due to its potential for exploitation via XSS.
2
How do I fix CVE-2017-8795?
To fix CVE-2017-8795, update your Accellion FTA devices to at least version FTA_9_12_180 or higher.
3
What type of vulnerability is CVE-2017-8795?
CVE-2017-8795 is a cross-site scripting (XSS) vulnerability found in the smtpg_add.html page.
4
What systems are affected by CVE-2017-8795?
CVE-2017-8795 affects Accellion Secure File Transfer Appliances running versions prior to FTA_9_12_180.
5
What are the implications of exploiting CVE-2017-8795?
Exploiting CVE-2017-8795 could allow an attacker to execute arbitrary scripts in the context of the user’s session.