PT-2021-24064 · Acronis · Acronis Cyber Protect 15+1

Frankiexote

·

Published

2021-11-25

·

Updated

2021-11-30

·

CVE-2021-44203

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Acronis Cyber Protect 15 (Windows, Linux) versions prior to build 28035
Description: A stored cross-site scripting (XSS) issue was possible in protection plan details. This type of issue allows an attacker to inject malicious scripts into content from otherwise trusted websites, which can lead to unauthorized actions on behalf of the user.
Recommendations: For Acronis Cyber Protect 15 (Windows, Linux) versions prior to build 28035, update to a version that is build 28035 or later to resolve the issue. As a temporary workaround, consider restricting access to the protection plan details feature until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-44203

Affected Products

Acronis
Acronis Cyber Protect 15