First published: Fri May 05 2017(Updated: )
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php allows SQL injection with the app_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion Secure File Transfer Appliance | <=9_12_40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8796 is considered a critical vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
To fix CVE-2017-8796, upgrade to Accellion FTA version 9_12_180 or later where the vulnerability is patched.
CVE-2017-8796 affects Accellion File Transfer Appliance devices running versions before 9_12_180.
CVE-2017-8796 is an SQL injection vulnerability that arises from improper input sanitization.
CVE-2017-8796 can allow attackers to manipulate database queries, potentially leading to data breaches or unauthorized access.