Vulnerabilities > Elkarbackup

DATE CVE VULNERABILITY TITLE RISK
2021-11-02 CVE-2020-35249 Cross-site Scripting vulnerability in Elkarbackup 1.3.3
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
network
low complexity
elkarbackup CWE-79
6.1
2020-09-15 CVE-2020-24925 Information Exposure Through an Error Message vulnerability in Elkarbackup 1.3.3
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3.
network
low complexity
elkarbackup CWE-209
7.5
2020-09-15 CVE-2020-24924 Cross-site Scripting vulnerability in Elkarbackup 1.3.3
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter
network
low complexity
elkarbackup CWE-79
5.4