CVE-2021-44201: Cross-site scripting (XSS) was possible in notification pop-ups
Published Nov 29, 2021
·Updated
Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
Affected Software
12 affected components
All of the following
Any of the following
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Any of the following
Linux Linux kernel
Microsoft Windows
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Nov 29, 2021
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2021-44201.
2
Which products are affected by this vulnerability?
Acronis Cyber Protect 15 (Windows, Linux) before build 28035 is affected.
3
What is the severity of the CVE-2021-44201 vulnerability?
The severity of the CVE-2021-44201 vulnerability is medium with a CVSS score of 6.1.
4
How can I fix the CVE-2021-44201 vulnerability?
To fix the CVE-2021-44201 vulnerability, you should update Acronis Cyber Protect 15 to a version equal to or later than build 28035.
5
Where can I find more information about the CVE-2021-44201 vulnerability?
You can find more information about the CVE-2021-44201 vulnerability in the Acronis Security Advisory SEC-3167.