Elkarbackup is a focused backup management application with a narrow product footprint, exposing recurring input-handling and information-disclosure weaknesses such as cross-site scripting flaws and overly verbose error messages. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elkarbackup over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-24925HIGH A Sensitive Source Code Path Disclosure vulnerability is found in ElkarBackup v1.3.3. An attacker is able to view the path of the source code jobs/sort where entire source code pat | Sep 15, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-35249MEDIUM Cross Site Scripting (XSS) vulnerability in ElkarBackup 1.3.3, allows attackers to execute arbitrary code via the name parameter to the add client feature. | Nov 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-24924MEDIUM A Persistent Cross-site Scripting vulnerability is found in ElkarBackup v1.3.3, where an attacker can steal the user session cookie using this vulnerability present on Policies >> | Sep 15, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elkarbackup.
Media articles that mention a CVE ID that affects a product developed by Elkarbackup — matched by CVE ID, not by vendor name.