QID 731204

Date Published: 2024-02-28

QID 731204: Accellion File Transfer Appliance (FTA) Multiple Security Vulnerabilities (CVE-2021-27101,CVE-2021-27104)

Accellion File Transfer Appliance is a file transfer application that is used to share files.

CVE-2021-27101: FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html.
CVE-2021-27104: FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints.

Affected Versions:
Accellion FTA versions 9_12_370 and earlier

Patch Versions:
Accellion FTA_version 9_12_380 and later

QID Detection Logic (Unauthenticated):
This QID detects Accellion File Transfer Appliance from WebUI.

Successful exploitation of these vulnerabilities may allow an attacker to either manipulate with database server or execute arbitrary command on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Please contact vendor Accellion for patch details.

    CVEs related to QID 731204

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-27101 URL Logo github.com/accellion/CVEs/blob/main/CVE-2021-27101.txt
    CVE-2021-27104 URL Logo github.com/accellion/CVEs/blob/main/CVE-2021-27104.txt