Vulnerabilities > Elkarbackup

DATE CVE VULNERABILITY TITLE RISK
2021-11-02 CVE-2020-35249 Cross-site Scripting vulnerability in Elkarbackup 1.3.3
Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature.
4.3
2020-09-15 CVE-2020-24925 Inadequate Encryption Strength vulnerability in Elkarbackup 1.3.3
A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3.
3.5
2020-09-15 CVE-2020-24924 Cross-site Scripting vulnerability in Elkarbackup 1.3.3
A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter
3.5