CVE detail
CVE-2023-48679 — CVE-2023-48679
Published 2024-02-27 · Modified 2026-06-17 · Vendor acronis · Product cyber_protect · Source nvd
MEDIUM
severity
CVSS-derived band
0.0026
EPSS probability
exploitation probability, 30d
18.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References