Impact
The vulnerability resides in the viewclient webpage of Quest NetVault Backup and allows a remote attacker to inject arbitrary scripts because user-supplied data is not properly validated. By exploiting this flaw, an attacker can bypass authentication and, when combined with other vulnerabilities, execute code with SYSTEM privileges. This leads to complete compromise of the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
Quest NetVault Backup installations that include the viewclient component are affected. The vulnerability is present in versions prior to the fix documented in the 14.0.2 release notes. Exact version ranges are not listed, so all installations using the viewclient should be considered at risk until patched.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. EPSS data is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Because user interaction is required—such as the target visiting a malicious page or opening a malicious file—the attacker must social engineer or otherwise induce the victim to trigger the exploit. Once activated, the authentication bypass can grant full control over the system.
OpenCVE Enrichment