vendor:
QuantaStor
by:
VVVSEC
6,1
CVSS
MEDIUM
User enumeration attack and two unauthenticated XSS
79, 203
CWE
Product Name: QuantaStor
Affected Version From: OSNEXUS QuantaStor v4 virtual appliance
Affected Version To: OSNEXUS QuantaStor v4 virtual appliance
Patch Exists: No
Related CWE: CVE-2017-9978, CVE-2017-9979
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
QuantaStor Software Define Storage mmultiple vulnerabilities
QuantaStor login mechanism returns different messages if the account used to perform the login is valid or not in the system. Leveraging this difference an attacker coould enumerate valid usernames in the system. Two different XSS were found in the appliance. The first one is located in the login page and the second one in the 'User Management' page.
Mitigation:
No mitigation available