CVE-2024-55541
CVSS 3.0 Score 3.1 of 10 (low)
Details
Summary
CVE-2024-55541 is a stored cross-site scripting (XSS) vulnerability affecting Acronis Cyber Protect 16 (Linux and Windows) before build 39169. The issue arises due to a missing origin validation in the postMessage function, allowing attackers to inject malicious scripts into websites that users visit after being initially compromised. Successful exploitation of this vulnerability could lead to unintended execution of malicious code, potentially resulting in data theft or other security breaches. Users are strongly advised to update their Acronis Cyber Protect software as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.