Description
Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5492 | Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615. |
References
| Link | Providers |
|---|---|
| https://security-advisory.acronis.com/advisories/SEC-7649 |
|
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Arbitrary file overwrite during home directory recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.8.4.866, Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.1.892, Acronis Backup extension for Plesk (Linux) before build 1.8.7.615. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Acronis
Published:
Updated: 2025-02-28T15:00:45.368Z
Reserved: 2025-01-24T21:09:13.772Z
Link: CVE-2025-24832
Updated: 2025-02-28T15:00:40.452Z
Status : Received
Published: 2025-02-27T23:15:37.310
Modified: 2025-02-27T23:15:37.310
Link: CVE-2025-24832
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD