TROYANOSYVIRUS
Back to CVEs

CVE-2017-8760

N/A

Description

An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.

CVE Details

CVSS v3.1 ScoreN/A
Published5/5/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0

Affected Products

accellion:file_transfer_appliance

Weaknesses (CWE)

CWE-79

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.