First published: Mon Feb 22 2021(Updated: )
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis Cyber Protect | <15 | |
Acronis Cyber Protect | =15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35664 is a vulnerability discovered in Acronis Cyber Protect before 15 Update 1 build 26172, which allows for cross-site scripting (XSS) attacks in the console.
Acronis Cyber Protect versions up to and including 15 Update 1 build 26172 are affected by CVE-2020-35664.
CVE-2020-35664 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2020-35664, it is recommended to update Acronis Cyber Protect to version 15 Update 1 build 26172 or later.
Cross-site scripting (XSS) is a type of vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.