CVE-2019-10263: XSS
Published Jul 26, 2019
·Updated
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account.
Affected Software
1 affected component
Ahsay Cloud Backup Suite<8.1.1.50
Event History
Jul 26, 2019
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10263?
The severity of CVE-2019-10263 is considered medium with a CVSS score of 6.1.
2
How can I exploit CVE-2019-10263?
An attacker can exploit CVE-2019-10263 by injecting XSS in the Alias field while creating a trial account to retrieve the admin's cookie and take over the account.