Vulnerability CVE-2023-48679


Published: 2024-02-27

Description:
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://security-advisory.acronis.com/advisories/SEC-3469

Copyright 2026, cxsecurity.com

 

Back to Top