First published: Wed May 18 2022(Updated: )
HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240
Credit: security@acronis.com
Affected Software | Affected Version | How to fix |
---|---|---|
Acronis Cyber Protect | <15 | |
Acronis Cyber Protect | =15 | |
Acronis Cyber Protect | =15-update1 | |
Acronis Cyber Protect | =15-update2 | |
Acronis Cyber Protect | =15-update3 | |
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30991 is a vulnerability that allows HTML injection via the report name in Acronis Cyber Protect 15 (Linux, Windows) before build 29240.
Acronis Cyber Protect 15 (Linux, Windows) before build 29240 is affected by CVE-2022-30991.
CVE-2022-30991 has a severity score of 6.1 (medium).
To fix CVE-2022-30991, update Acronis Cyber Protect 15 (Linux, Windows) to build 29240 or later.
You can find more information about CVE-2022-30991 at the following link: https://security-advisory.acronis.com/advisories/SEC-3928