VYPR
Medium severity6.1NVD Advisory· Published Jan 2, 2025· Updated Jun 17, 2026

CVE-2024-55541

CVE-2024-55541

Description

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.

Affected products

6
  • cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*range: <=15
    • cpe:2.3:a:acronis:cyber_protect:16:-:*:*:*:*:*:*
    • cpe:2.3:a:acronis:cyber_protect:16:update1:*:*:*:*:*:*
    • cpe:2.3:a:acronis:cyber_protect:16:update2:*:*:*:*:*:*
    • (no CPE)range: < build 39169
  • Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.