Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 23:15:00 +0000

Type Values Removed Values Added
Description Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.
Weaknesses CWE-61
References
Metrics cvssV3_0

{'score': 4.4, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Acronis

Published:

Updated: 2025-02-28T15:00:45.368Z

Reserved: 2025-01-24T21:09:13.772Z

Link: CVE-2025-24832

cve-icon Vulnrichment

Updated: 2025-02-28T15:00:40.452Z

cve-icon NVD

Status : Received

Published: 2025-02-27T23:15:37.310

Modified: 2025-02-27T23:15:37.310

Link: CVE-2025-24832

cve-icon Redhat

No data.