CVE-2024-49392 MEDIUM

CVE-2024-49392

Vendor Acronis
Product Acronis Cyber Files
Weakness CWE-79 · XSS
Published October 17, 2024
Last update October 17, 2024

CVSS base score

5.7/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.

Key dates

02Disclosure timeline

October 17, 2024 CVE published
October 17, 2024 Record updated

Related vulnerabilities

04Related CVE