CVE-2017-8304: Accellion File Transfer Appliance

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered on Accellion FTA devices before FTA_9_12_180. courier/1000@/oauth/playground/callback.html allows XSS with a crafted URI.

Affected products

  • Accellion File Transfer Appliance: up to and including 9_12_40

Published 2017-05-05. Last modified 2026-06-17.