CVE-2021-37216
02.08.2021, 12:15
QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.
| Vendor | Product | Version |
|---|---|---|
| qsan | xn8024r_firmware | 3.1.5 |
| qsan | xn8008t_firmware | 3.3.2 |
𝑥
= Vulnerable software versions