Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xwvv-pqhf-w6qv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

EPSS

Процентиль: 88%
0.0404
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
около 4 лет назад

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

EPSS

Процентиль: 88%
0.0404
Низкий

Дефекты

CWE-79