CVE-2021-44202: Stored cross-site scripting (XSS) was possible in activity details
Published Nov 29, 2021
·Updated
Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
Affected Software
12 affected components
All of the following
Any of the following
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Any of the following
Linux Linux kernel
Microsoft Windows
Acronis Cyber Protect<15
Acronis Cyber Protect=15
Acronis Cyber Protect=15-update1
Acronis Cyber Protect=15-update2
Linux Linux kernel
Microsoft Windows
Remediation
Patch Available
Event History
Nov 29, 2021
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-44202?
The severity of CVE-2021-44202 is medium with a CVSS score of 5.4.
2
Which products are affected by CVE-2021-44202?
Acronis Cyber Protect 15 (Windows, Linux) before build 28035 is affected by CVE-2021-44202.
3
How can an attacker exploit CVE-2021-44202?
An attacker can exploit CVE-2021-44202 by performing stored cross-site scripting (XSS) attacks in activity details.
4
What is the fix for CVE-2021-44202?
To fix CVE-2021-44202, update to Acronis Cyber Protect 15 build 28035 or a higher version.
5
Where can I find more information about CVE-2021-44202?
You can find more information about CVE-2021-44202 in the Acronis security advisory at the following link: [CVE-2021-44202](https://security-advisory.acronis.com/advisories/SEC-3283).