ZeroHour

CVE-2019-10263

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p55
Published
()
Modified
Description

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the attacker to retrieve the admin's cookie and take over the account.

Vendors
ahsay
Products
cloud backup suite
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.