QSAN Storage Manager是广盛科技股份有限公司(QSAN)的一个NAS操作系统。 QSAN Storage Manager存在安全漏洞,该漏洞源于标题页参数不过滤特殊字符。远程攻击者可以在不登录的情况下注入 JavaScript 并发起反射型 XSS 攻击来访问和修改特定数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| QSAN | Storage Manager XN8008T | unspecified ~ 3.3.2 | - |
|
| QSAN | Storage Manager XN8024R | unspecified ~ 3.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | QSAN Storage Manager before 3.3.3 contains a reflected cross-site scripting vulnerability. Header page parameters do not filter special characters. Remote attackers can inject JavaScript to access and modify specific data. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-37216.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet