Vulnerability Description
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elkarbackup | Elkarbackup | 1.3.3 |
Related Weaknesses (CWE)
References
- https://github.com/sooraj24/new/blob/master/XSS%20in%20ElkarBackupExploitThird Party Advisory
- https://vyshnavvizz.blogspot.com/2020/09/stored-cross-site-scripting-in.htmlExploitThird Party Advisory
- https://www.elkarbackup.org/Product
- https://github.com/sooraj24/new/blob/master/XSS%20in%20ElkarBackupExploitThird Party Advisory
- https://vyshnavvizz.blogspot.com/2020/09/stored-cross-site-scripting-in.htmlExploitThird Party Advisory
- https://www.elkarbackup.org/Product
FAQ
What is CVE-2020-24924?
CVE-2020-24924 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Param...
How severe is CVE-2020-24924?
CVE-2020-24924 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24924?
Check the references section above for vendor advisories and patch information. Affected products include: Elkarbackup Elkarbackup.