XSS Vulnerability in Ahsay Cloud Backup Suite
CVE-2019-10263

6.1MEDIUM

Key Information:

Vendor

Ahsay

Vendor
CVE Published:
26 July 2019

What is CVE-2019-10263?

A vulnerability has been identified in Ahsay Cloud Backup Suite prior to version 8.1.1.50, allowing attackers to exploit the system when users create trial accounts. By injecting malicious code into the Alias field, an attacker can execute cross-site scripting (XSS), enabling them to capture the administrator's cookies and potentially gain unauthorized access to the account. This poses a significant security risk for users relying on Ahsay for data backup solutions.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.