ZeroHour
Full Disclosurepublished ()ingested
Part of a story covered by 2 sources: “0day Rubbish Research Team discloses two CVSS 8.8 command injection flaws: QuantaStor 6.8.3.018 alert-mail smtpPassword injection and persistent OP5 Monitor 9.20 injection despite…” — merged summary and timeline →

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

mediumVulnerabilityimportance 38
AI summary · glm-5.3-flash

QuantaStor 6.8.3.018 has a CVSS 8.8 command injection in its alert-mail command, exploitable via the smtpPassword field.

0day Rubbish Research Team disclosed a command injection (CWE-78) in QuantaStor 6.8.3.018's alert-mail command, reachable through the smtpPassword field. The flaw scores CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). No CVE identifier or evidence of active exploitation is mentioned in the disclosure.

  • Command injection (CWE-78) in the QuantaStor alert-mail command via the smtpPassword field
  • CVSS 8.8 network vector with low-privilege requirement and high C/I/A impact
  • Disclosed publicly as a 0day without mention of active exploitation
Full article

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in QuantaStor 6.8.3.018. Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact:...

This source does not provide full text. Read it at seclists.org.