CVE-2021-27730
https://notcve.org/view.php?id=CVE-2021-27730
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later. Accellion FTA versiones 9_12_432 y anteriores, está afectado por una inyección de argumentos por medio de una petición POST diseñada para un endpoint de administración. La versión fija es FTA_9_12_444 y posteriores • https://github.com/accellion/CVEs/blob/main/CVE-2021-27730.txt • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •
CVE-2021-27731
https://notcve.org/view.php?id=CVE-2021-27731
Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later. Accellion FTA versiones 9_12_432 y anteriores, está afectado por una vulnerabilidad de tipo XSS almacenado por medio de una petición POST diseñada para un endpoint de usuario. La versión corregida es FTA _9_12_444 y posteriores • https://github.com/accellion/CVEs/blob/main/CVE-2021-27731.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2021-27104 – Accellion FTA OS Command Injection Vulnerability
https://notcve.org/view.php?id=CVE-2021-27104
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later. Accellion versiones FTA 9_12_370 y anteriores, está afectada por una ejecución de comandos del Sistema Operativo por medio de una petición POST diseñada para varios endpoints de administración. La versión corregida es FTA_9_12_380 y posteriores Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints. • https://github.com/accellion/CVEs/blob/main/CVE-2021-27104.txt https://www.accellion.com/products/fta • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2021-27103 – Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability
https://notcve.org/view.php?id=CVE-2021-27103
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later. Accellion versiones FTA 9_12_411 y anteriores, están afectadas por una vulnerabilidad de tipo SSRF por medio de una petición POST diseñada para el archivo wmProgressstat.html. La versión corregida es FTA_9_12_416 y posteriores Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html. • https://github.com/accellion/CVEs/blob/main/CVE-2021-27103.txt https://www.accellion.com/products/fta • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2021-27102 – Accellion FTA OS Command Injection Vulnerability
https://notcve.org/view.php?id=CVE-2021-27102
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later. Accellion versiones FTA 9_12_411 y anteriores, está afectada por una ejecución de comandos del Sistema Operativo por medio de una llamada de servicio web local. La versión corregida es FTA_9_12_416 y posteriores Accellion FTA contains an OS command injection vulnerability exploited via a local web service call. • https://github.com/accellion/CVEs/blob/main/CVE-2021-27102.txt https://www.accellion.com/products/fta • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •