CVE-2020-24924: Elkarbackup

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> action >> Name Parameter

Affected products

Published 2020-09-15. Last modified 2026-06-17.