CVE-2024-49392: XSS
Published Oct 17, 2024
·Updated
Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
Affected Software
1 affected component
Acronis Cyber Files Windows<9.0
Event History
Oct 17, 2024
CVE Published
via MITRE·09:48 AM
Data Sourced
via MITRE·09:48 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49392?
CVE-2024-49392 has been rated as a medium severity stored cross-site scripting vulnerability.
2
How do I fix CVE-2024-49392?
To fix CVE-2024-49392, update Acronis Cyber Files to version 9.0.0x24 or later.
3
Which products are affected by CVE-2024-49392?
CVE-2024-49392 affects Acronis Cyber Files (Windows) versions prior to build 9.0.0x24.
4
What type of vulnerability is CVE-2024-49392?
CVE-2024-49392 is a stored cross-site scripting (XSS) vulnerability.
5
Can CVE-2024-49392 lead to data compromise?
Yes, CVE-2024-49392 can potentially allow attackers to inject malicious scripts and compromise user data.