PoC Index

CVE-2021-37216

MEDIUM 6.1EPSS 3.2%

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
3.19% chance of exploitation in the next 30 days, 87th percentile
Nuclei
medium · CWE-79
Published
2021-08-02
Updated
2024-09-16

Nuclei templates (1)

References

Related