Description
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
Published: 2021-08-02
Score: 6.1 Medium
EPSS: 4.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update QSAN Storage Manager to version 3.3.3

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-23790 QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
History

No history.

Subscriptions

Qsan Xn8008t Xn8008t Firmware Xn8024r Xn8024r Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-16T21:57:49.436Z

Reserved: 2021-07-21T00:00:00.000Z

Link: CVE-2021-37216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-02T12:15:08.183

Modified: 2024-11-21T06:14:52.983

Link: CVE-2021-37216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses