Show filters
42 Total Results
Displaying 1-10 of 42
Sort by:
Attacker Value
Very High

CVE-2021-27101

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
Attacker Value
Unknown

CVE-2022-24110

Disclosure Date: February 14, 2022 (last updated October 07, 2023)
Kiteworks MFT 7.5 may allow an unauthorized user to reset other users' passwords. This is fixed in version 7.6 and later.
Attacker Value
Unknown

CVE-2021-31586

Disclosure Date: June 23, 2021 (last updated February 22, 2025)
Accellion Kiteworks before 7.4.0 allows an authenticated user to perform SQL Injection via LDAPGroup Search.
Attacker Value
Unknown

CVE-2021-31585

Disclosure Date: June 23, 2021 (last updated November 28, 2024)
Accellion Kiteworks before 7.3.1 allows a user with Admin privileges to escalate their privileges by generating SSH passwords that allow local access.
Attacker Value
Unknown

CVE-2021-27730

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_432 and earlier is affected by argument injection via a crafted POST request to an admin endpoint. The fixed version is FTA_9_12_444 and later.
Attacker Value
Unknown

CVE-2021-27731

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed version is FTA_9_12_444 and later.
Attacker Value
Unknown

CVE-2021-27104

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
Attacker Value
Unknown

CVE-2021-27103

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed version is FTA_9_12_416 and later.
Attacker Value
Unknown

CVE-2021-27102

Disclosure Date: February 16, 2021 (last updated February 22, 2025)
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
Attacker Value
Unknown

The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to informa…

Disclosure Date: July 13, 2018 (last updated November 27, 2024)
Accellion FTP server prior to version FTA_9_12_220 uses the Accusoft Prizm Content flash component, which contains multiple parameters (customTabCategoryName, customButton1Image) that are vulnerable to cross-site scripting.
0