Loading
An issue was discovered on Accellion FTA devices before FTA_9_12_180. Because a regular expression (intended to match local https URLs) lacks an initial ^ character, courier/web/1000@/wmProgressval.html allows SSRF attacks with a file:///etc/passwd#https:// URL pattern.
Use CWE-918, Accellion vendor hub and File Transfer Appliance product page to widen CVE-2017-8794 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-5623, CVE-2019-5622 and CVE-2015-2857 for nearby disclosures in the same product family.