CVE-2021-27101 is a critical SQL injection vulnerability affecting Accellion FTA versions 9_12_370 and earlier, allowing attackers to manipulate database queries via a crafted Host header. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, notably by the Clop ransomware gang, and has garnered significant community attention and media coverage, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. Organizations using affected versions are urged to upgrade to FTA_9_12_380 or later immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9_12_370CPE matchmatch criteria | cpe:2.3:a:accellion:fta:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.