Reflected XSS vulnerability in OSNEXUS QuantaStor before 6.0.0.355
Vulnerability Description
An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)>
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-42080
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Wietse Boonstra (DIVD)
- Frank Breedijk (DIVD)
- Victor Pasman (DIVD)
- Victor Gevers (DIVD)
- Max van der Horst (DIVD)
- Célistine Oosting (DIVD)
References
More from OSNEXUS
View All →Affected Vendor
OSNEXUS
View all reports →