An issue exists in Ahsay Cloud Backup Suite prior to 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen has an Import Users option. This option accepts a ZIP archive containing a users.xml file that can trigger XXE.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ahsay cloud backup suite |