CVE-2024-49392

Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:acronis:cyber_files:*:*:*:*:*:windows:*:*

History

18 Oct 2024, 20:10

Type Values Removed Values Added
References () https://security-advisory.acronis.com/advisories/SEC-7554 - () https://security-advisory.acronis.com/advisories/SEC-7554 - Vendor Advisory
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:acronis:cyber_files:*:*:*:*:*:windows:*:*
First Time Acronis
Acronis cyber Files

18 Oct 2024, 12:52

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de cross-site scripting (XSS) almacenado en la página de invitación a la inscripción. Los siguientes productos están afectados: Acronis Cyber Files (Windows) antes de la compilación 9.0.0x24.

17 Oct 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-17 10:15

Updated : 2024-10-18 20:10


NVD link : CVE-2024-49392

Mitre link : CVE-2024-49392

CVE.ORG link : CVE-2024-49392


JSON object : View

Products Affected

acronis

  • cyber_files
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')