CVE-2021-38087: XSS
Published Aug 12, 2021
·Updated
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
Affected Software
3 affected components
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Event History
Aug 12, 2021
CVE Published
via MITRE·01:44 PM
Data Sourced
via MITRE·01:44 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-38087.
2
What is the severity level of CVE-2021-38087?
CVE-2021-38087 has a severity level of medium (6.1).
3
How does the vulnerability impact Acronis Cyber Protect 15?
The reflected cross-site scripting (XSS) vulnerability in CVE-2021-38087 could allow attackers to execute malicious scripts on the login page of Acronis Cyber Protect 15 prior to build 27009.
4
Has Acronis provided a fix for CVE-2021-38087?
Yes, Acronis has provided a fix for CVE-2021-38087. It is recommended to update to build 27009 or later to resolve the vulnerability.
5
Where can I find more information about CVE-2021-38087?
More information about CVE-2021-38087 can be found at the Acronis Knowledge Base article: https://kb.acronis.com/content/68564