Qstar

Archive Storage Manager

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.18%
  • Veröffentlicht 13.01.2024 04:15:08
  • Zuletzt bearbeitet 16.06.2025 19:15:25

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 13.01.2024 04:15:08
  • Zuletzt bearbeitet 03.06.2025 14:15:35

An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 13.01.2024 04:15:08
  • Zuletzt bearbeitet 21.11.2024 08:37:47

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 13.01.2024 04:15:08
  • Zuletzt bearbeitet 03.06.2025 14:15:35

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 13.01.2024 04:15:07
  • Zuletzt bearbeitet 16.06.2025 19:15:24

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command.

Exploit
  • EPSS 0.11%
  • Veröffentlicht 13.01.2024 04:15:07
  • Zuletzt bearbeitet 03.06.2025 14:15:35

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 13.01.2024 04:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:46

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 13.01.2024 04:15:07
  • Zuletzt bearbeitet 16.06.2025 19:15:25

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server.

Exploit
  • EPSS 9%
  • Veröffentlicht 13.01.2024 04:15:07
  • Zuletzt bearbeitet 06.06.2025 20:15:21

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.