CVE-2021-27101
Description
Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.html. The fixed version is FTA_9_12_380 and later.
In plain language
AI Act nowAccellion FTA up to FTA_9_12_370 can be tricked with a fake Host header to break into the database, so a typical small business running it should treat this as an urgent fix (resolved in FTA_9_12_380 and later).
CVE-2021-27101 is a SQL injection weakness in Accellion FTA (FTA_9_12_370 and earlier) triggered via a crafted Host header in a request to document_root.html; it has been confirmed in real-world ransomware campaigns and listed in CISA KEV.
What to do now
- Check whether your Accellion FTA version is FTA_9_12_370 or earlier (or not obviously FTA_9_12_380+).
- If you are on an affected version, plan an immediate upgrade to Accellion FTA FTA_9_12_380 (and later) using the vendor’s update instructions.
- Confirm after the upgrade that the system is running the fixed release (FTA_9_12_380+) and that updates took effect.
- If you cannot upgrade right away, contact your vendor/IT support to apply the vendor’s interim mitigations from the provided guidance, and restrict access while waiting for the patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-27101 and every CVE in our database. Create a free account — no credit card required.
Create Free Account