Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
2024-02-27T17:15:10.617
2025-02-06T16:30:48.253
Analyzed
CVSSv3.1: 5.4 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | acronis | cyber_protect | < 16 | Yes |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |