Medium severity6.1NVD Advisory· Published Jan 2, 2025· Updated Jun 17, 2026
CVE-2024-55541
CVE-2024-55541
Description
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 39169.
Affected products
6cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:acronis:cyber_protect:*:*:*:*:*:*:*:*range: <=15
- cpe:2.3:a:acronis:cyber_protect:16:-:*:*:*:*:*:*
- cpe:2.3:a:acronis:cyber_protect:16:update1:*:*:*:*:*:*
- cpe:2.3:a:acronis:cyber_protect:16:update2:*:*:*:*:*:*
- (no CPE)range: < build 39169
- Range: unspecified
Patches
Vulnerability mechanics
References
1- security-advisory.acronis.com/advisories/SEC-3647nvdVendor Advisory
News mentions
0No linked articles in our index yet.