CyberSec.Space Logo
Back to CVE Browser

CVE-2017-8794

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1520%
EPSS Percentile0.59th
PublishedMay 5, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

Affected Platforms (CPE)

📦
Accellion

File Transfer Appliance

<= 9_12_40

References & Advisories

Related Vulnerabilities