An issue was discovered on Accellion FTA devices before FTA912180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/useradd.html with the param parameter.
An issue was discovered on Accellion FTA devices before FTA912180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.
An issue was discovered on Accellion FTA devices before FTA912180. There is a home/seos/courier/login.html authparams CRLF attack vector.
An issue was discovered on Accellion FTA devices before FTA912180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in home/seos/courier/smtpgadd.html with the param parameter.
An issue was discovered on Accellion FTA devices before FTA912180. There is a CRLF vulnerability in settingsglobaltextedit.php allowing ?display=x%0Dnewline attacks.
An issue was discovered on Accellion FTA devices before FTA912180. Because mysqlrealescapestring is misused, seos/courier/communicationp2p.php allows SQL injection with the appid parameter.
An issue was discovered on Accellion FTA devices before FTA912180. A reporterror.php?year='payload SQL injection vector exists.
An issue was discovered on Accellion FTA devices before FTA912180. There is XSS in courier/1000@/index.html with the authparams parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.
An issue was discovered on Accellion FTA devices before FTA912180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.