An authenticated attacker is able to create alerts that trigger a stored XSS attack.

POC


* go to the alert manager


* open the ITSM tab
* add a webhook with the URL/service token value

' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters)


* click add


* click apply


* create a test alert


* The test alert will run the command

“id | tee /tmp/ttttttddddssss” as root.


* after the test alert inspect

/tmp/ttttttddddssss it'll contain the ids of the root user.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-29069 An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * click add * click apply * create a test alert * The test alert will run the command “id | tee /tmp/ttttttddddssss” as root. * after the test alert inspect /tmp/ttttttddddssss it'll contain the ids of the root user.
Fixes

Solution

Upgrade to the latest version of OSNEXUS QuantaStor.


Workaround

No workaround given by the vendor.

History

Mon, 22 Sep 2025 06:45:00 +0000

Type Values Removed Values Added
Description An authenticated attacker is able to create alerts that trigger a stored XSS attack. An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab characters) * click add * click apply * create a test alert * The test alert will run the command “id | tee /tmp/ttttttddddssss” as root. * after the test alert inspect /tmp/ttttttddddssss it'll contain the ids of the root user.

Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 16 Oct 2024 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 16 Oct 2024 12:00:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published:

Updated: 2025-09-22T06:40:07.586Z

Reserved: 2021-10-07T17:12:57.678Z

Link: CVE-2021-42083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-07-10T16:15:47.690

Modified: 2025-09-22T07:15:40.060

Link: CVE-2021-42083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.