4.3
CVSSv2

CVE-2019-10263

Published: 26/07/2019 Updated: 31/07/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in Ahsay Cloud Backup Suite prior to 8.1.1.50. When creating a trial account, it is possible to inject XSS in the Alias field, allowing the malicious user to retrieve the admin's cookie and take over the account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ahsay cloud backup suite

Exploits

Ahsay Backup versions 7x through 81150 suffer from an XML external entity injection vulnerability ...