VulnerabilityModified
CVE-2021-37216
Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
MEDIUM 6.1EPSS 3.16%
Does this matter?
Lower severity and a low EPSS score (3.16%). Track it; it rarely justifies an emergency change on its own.
Description
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- qsan/xn8024r firmware · qsan/xn8008t firmware
- Source
- twcert@cert.org.tw
References
- https://www.twcert.org.tw/tw/cp-132-4962-44cd2-1.htmlThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4962-44cd2-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.