PT-2021-24064 · Acronis · Acronis Cyber Protect 15+1
Frankiexote
·
Published
2021-11-25
·
Updated
2021-11-30
·
CVE-2021-44203
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Acronis Cyber Protect 15 (Windows, Linux) versions prior to build 28035
Description:
A stored cross-site scripting (XSS) issue was possible in protection plan details. This type of issue allows an attacker to inject malicious scripts into content from otherwise trusted websites, which can lead to unauthorized actions on behalf of the user.
Recommendations:
For Acronis Cyber Protect 15 (Windows, Linux) versions prior to build 28035, update to a version that is build 28035 or later to resolve the issue. As a temporary workaround, consider restricting access to the protection plan details feature until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acronis
Acronis Cyber Protect 15