Loading HuntDB...

GHSA-x9r2-f53m-rgrx

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An issue was discovered on Accellion FTA devices before FTA_9_12_180. By sending a POST request to home/seos/courier/web/wmProgressstat.html.php with an attacker domain in the acallow parameter, the device will respond with an Access-Control-Allow-Origin header allowing the attacker to have site access with a bypass of the Same Origin Policy.

Related CVEs

Key Information

GHSA ID
GHSA-x9r2-f53m-rgrx
Published
May 13, 2022 1:47 AM
Last Modified
May 13, 2022 1:47 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.