vendor:
ElkarBackup
by:
Enes Özeser
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: ElkarBackup
Affected Version From: 1.3.2003
Affected Version To: 1.3.2003
Patch Exists: NO
Related CWE:
CPE: a:elkarbackup_project:elkarbackup:1.3.3
Platforms Tested: Linux
2020
ElkarBackup 1.3.3 – Persistent Cross-Site Scripting
The ElkarBackup version 1.3.3 is vulnerable to persistent cross-site scripting. An attacker can inject malicious scripts through the 'Name' section when adding a client, leading to the execution of arbitrary code on the user's browser.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input before displaying it on web pages and implement proper input validation and output encoding.