CVE-2017-8796: SQL Injection
Published May 5, 2017
·Updated
An issue was discovered on Accellion FTA devices before FTA912180. Because mysqlrealescapestring is misused, seos/courier/communicationp2p.php allows SQL injection with the appid parameter.
Affected Software
1 affected component
Accellion File Transfer Appliance<=9_12_40
Event History
May 5, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8796?
CVE-2017-8796 is considered a critical vulnerability due to its potential for SQL injection, which can lead to unauthorized data access.
2
How do I fix CVE-2017-8796?
To fix CVE-2017-8796, upgrade to Accellion FTA version 9_12_180 or later where the vulnerability is patched.
3
What systems are affected by CVE-2017-8796?
CVE-2017-8796 affects Accellion File Transfer Appliance devices running versions before 9_12_180.
4
What type of vulnerability is CVE-2017-8796?
CVE-2017-8796 is an SQL injection vulnerability that arises from improper input sanitization.
5
What impacts can CVE-2017-8796 have on an organization?
CVE-2017-8796 can allow attackers to manipulate database queries, potentially leading to data breaches or unauthorized access.