PT-2024-14043 · Unknown · Qstar Archive Solutions

Published

2024-01-13

·

Updated

2024-01-19

·

CVE-2023-51064

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QStar Archive Solutions version RELEASE 3-0 Build 7 Patch 0
Description A DOM Based reflected XSS issue was found in the qnme-ajax component, specifically in the "method=tree table" part. This could potentially allow for malicious script execution.
Recommendations For QStar Archive Solutions version RELEASE 3-0 Build 7 Patch 0, consider restricting access to the qnme-ajax component, especially the "method=tree table" endpoint, until a fix is available. As a temporary workaround, avoid using the qnme-ajax component with the "method=tree table" parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-51064

Affected Products

Qstar Archive Solutions