Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Quantastor HIGH 7.8
CVE-2021-42082

Local users are able to execute scripts under root privileges. POC On the local host run the following command: curl 'localhost:8154/qstor/qs_upgr…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Quantastor HIGH 7.4
CVE-2021-42080

An attacker is able to launch a Reflected XSS attack using a crafted URL. POC: Visit the following URL https://<IPADDRESS>:8153/qstorapi/echo?input…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Quantastor HIGH 7.2
CVE-2021-42081

An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemMo…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Quantastor HIGH 7.2
CVE-2021-4406

An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab *…

Fix: 6.0.0.355+
Fix from $1,950 2023-07-10
Quantastor MEDIUM 5.4
CVE-2021-42083

An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab *…

Fix: 6.0.0.355+
Fix from $1,600 2023-07-10
Quantastor MEDIUM 6.1
CVE-2017-9979

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the inval…

Fix: after 4.3.0
Fix from $1,600 2017-08-28
Quantastor MEDIUM 5.3
CVE-2017-9978

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on…

Fix: after 4.3.0
Fix from $1,600 2017-08-28