Loading HuntDB...

GHSA-xwvv-pqhf-w6qv

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

QSAN Storage Manager header page parameters does not filter special characters. Remote attackers can inject JavaScript without logging in and launch reflected XSS attacks to access and modify specific data.

Related CVEs

Key Information

GHSA ID
GHSA-xwvv-pqhf-w6qv
Published
May 24, 2022 7:09 PM
Last Modified
May 24, 2022 7:09 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 7, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.