peter bassill · operator
$ cve CVE-2017-9979 JSON

CVE-2017-9979 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can leverage this issue by including arbitrary HTML or JavaScript code as a parameter, aka XSS.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.56% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2017-08-28
Last modified2026-06-17

Affected (1)

VendorProduct
osnexusquantastor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD