An issue exists in Ahsay Cloud Backup Suite prior to 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the malicious user to retrieve the admin's cookie and take over the account.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ahsay cloud backup suite |