CVE-2015-2856: Accellion File Transfer Appliance
High severity, CVSS 7.5. EPSS: 56.6% chance of exploitation in the next 30 days.
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices before FTA_9_11_210 allows remote attackers to read arbitrary files via a .. (dot dot) in the statecode cookie.
Affected products
- Accellion File Transfer Appliance: up to and including fta_9_11_200
Published 2017-10-10. Last modified 2026-06-17.