Record summary

CVE-2017-9979 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBQuantaStor Software Defined Storage < 4.3.1 - Multiple VulnerabilitiesExploitDB exploitby VVVSecurityNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

5