← Vulnerability feed

Vulnerability record · CVE-2017-8794 · published 5 May 2017

CVE-2017-8794: Accellion file transfer appliance server-side request forgery (ssrf) vulnerability

Accellion · File Transfer Appliance

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

10.0 CVSS 3.0 Critical EPSS 1.9% · top 21.2% CWE-918 · Server-side request forgery (SSRF)
10.0CVSS 3.0 base score, v2 6.4
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-8794 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-5622Accellion file transfer appliance hard-coded credentials vulnerabilityAccellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-798: Use of Hard-coded Credentials.EPSS 1.1%9.8CVE-2019-5623Accellion file transfer appliance command injection vulnerabilityAccellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Special Elements used in a Comma…EPSS 1.6%9.8CVE-2015-2857Accellion File Transfer Appliance command injection via oauth_tokenAccellion File Transfer Appliance before FTA_9_11_210 passes the oauth_token parameter to a shell without sanitizing metacharacters, allowing command…EPSS 84%analysed9.8CVE-2017-8303Accellion file transfer appliance vulnerabilityAn issue was discovered on Accellion FTA devices before FTA_9_12_180. seos/1000/find.api allows Remote Code Execution with shell metacharacters in th…EPSS 24%9.8CVE-2017-8789Accellion file transfer appliance sql injection vulnerabilityAn issue was discovered on Accellion FTA devices before FTA_9_12_180. A report_error.php?year='payload SQL injection vector exists.EPSS 1.2%9.8CVE-2017-8790Accellion file transfer appliance ldap injection vulnerabilityAn issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDA…EPSS 1.4%9.8CVE-2017-8796Accellion file transfer appliance sql injection vulnerabilityAn issue was discovered on Accellion FTA devices before FTA_9_12_180. Because mysql_real_escape_string is misused, seos/courier/communication_p2p.php…EPSS 1.2%9.8CVE-2016-2351Accellion file transfer appliance sql injection vulnerabilitySQL injection vulnerability in home/seos/courier/security_key2.api on the Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote at…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2017-8794), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.