go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

QSAN Storage Manager - Reflected Cross-Site Scripting

TVN ID TVN-202107010
CVE ID CVE-2021-37216
CVSS 6.1 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products QSAN Storage Manager XN8008T v3.3.2
QSAN Storage Manager XN8024R v3.1.5
Description QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
Solution Update QSAN Storage Manager to version 3.3.3
Credit Dwi Siswanto
Public Date 2021-07-30
Top