QSAN Storage Manager before 3.3.3 contains a reflected cross-site scripting vulnerability. Header page parameters do not filter special characters. Remote attackers can inject JavaScript to access and modify specific data.
id: CVE-2021-37216
info:
name: QSAN Storage Manager <3.3.3 - Cross-Site Scripting
author: dwisi
...