QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.twcert.org.tw/tw/cp-132-4962-44cd2-1.html |
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2021-08-02T11:18:56.385206Z
Updated: 2024-09-16T21:57:49.436Z
Reserved: 2021-07-21T00:00:00
Link: CVE-2021-37216
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-02T12:15:08.183
Modified: 2024-11-21T06:14:52.983
Link: CVE-2021-37216
Redhat
No data.