Impact
OSNexus QuantaStor SDS Manager contains an unauthenticated SQL injection flaw in its login endpoint. The application fails to sanitize the username field before incorporating it into a SQL query, enabling an attacker to craft payloads that bypass authentication and obtain administrator credentials without a valid password. Once logged in as an administrator, the attacker gains full control over the system, allowing configuration changes, data theft, service disruption, or deployment of further malware. The vulnerability affects confidentiality, integrity, and availability by providing unrestricted administrative access.
Affected Systems
The affected product is OSNexus QuantaStor SDS Manager. No specific version information is listed, so the vulnerability could potentially affect all current releases of the SDS Manager until a patch is applied.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability with a likelihood of serious impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. An attacker does not need any authentication to exploit the flaw; simply a crafted request to the public login endpoint is sufficient. The exploitation requires only network access to the SDS Manager and no additional privileges.
OpenCVE Enrichment