6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
Affected (2)
Products: Qsan: Xn8024r Firmware, Xn8008t Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.1.5 |
| Running on/with | Platform Versions |
|---|---|
Qsan Xn8024r | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.3.2 |
| Running on/with | Platform Versions |
|---|---|
Qsan Xn8008t | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.