CVE-2021-27731: XSS
Published Mar 2, 2021
·Updated
Accellion FTA 912432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA912444 and later.
Affected Software
1 affected component
Accellion FTA<=9_12_432
Event History
Mar 2, 2021
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-27731.
2
What is the severity of CVE-2021-27731?
The severity of CVE-2021-27731 is medium (6.1).
3
How does the vulnerability affect Accellion FTA?
Accellion FTA 9_12_432 and earlier is affected by stored Cross-Site Scripting (XSS) through a crafted POST request to a user endpoint.
4
What is the fixed version for CVE-2021-27731?
The fixed version for CVE-2021-27731 is FTA_9_12_444 and later.
5
What is the CWE ID associated with CVE-2021-27731?
The CWE ID associated with CVE-2021-27731 is 79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).