Beveiligingsadvies

CVE-2026-10880

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-04 17:19:33
Laatst bijgewerkt 2026-06-04 18:10:36
Toegewezen door BLSOPS
CVSS-score 9.8
Status PUBLISHED

Beschrijving

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.