Impact
This vulnerability in Veeam Backup Enterprise Manager allows an attacker to execute script code in the browser of a portal user who opens a crafted link. The flaw is an instance of cross‑site scripting (CWE‑79), enabling the attacker to run code within the victim’s browser context.
Affected Systems
The affected product is Veeam Backup Enterprise Manager. Version details were not disclosed in the advisory, so all installations of the product could potentially be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate overall risk. No EPSS score is available, and the vulnerability is not listed in the CISA known‑exploited catalog. The attack vector is inferred to be a remote web‑based threat where a malicious link is opened by an authenticated portal user, allowing script execution in the victim’s browser. No additional attack prerequisites are described, and no public exploits have been reported in the available information.
OpenCVE Enrichment