qstar CVE Vulnerabilities & CVE List (9)

Products (CPE): — CVEs: 9

qstar vulnerability overview

Aggregates CVE and security vulnerability intelligence across all qstar-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting and vendor risk csrf; exposure may include vendor impact session compromise in vendor surface automated decompression and vendor surface archive handling contexts.

Vulnerability distribution trend (last 24 months)

Showing 19 of 9 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-51071 An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a victim's Qstar instance by executing a specific command in a link. [email protected] 6.5 0.13% 2024-01-13 2025-06-03
CVE-2023-51070 An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the QStar Server. [email protected] 7.5 0.23% 2024-01-13 2024-11-21
CVE-2023-51068 An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. [email protected] 5.4 0.20% 2024-01-13 2025-06-03
CVE-2023-51067 An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser via a crafted link. [email protected] 6.1 0.18% 2024-01-13 2025-06-16
CVE-2023-51066 An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands. [email protected] 8.8 9.00% 2024-01-13 2025-06-06
CVE-2023-51065 Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from the QStar Server. [email protected] 7.5 0.58% 2024-01-13 2025-06-16
CVE-2023-51064 QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table. [email protected] 6.1 0.12% 2024-01-13 2025-06-20
CVE-2023-51063 QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component qnme-ajax?method=tree_level. [email protected] 8.8 0.06% 2024-01-13 2025-06-03
CVE-2023-51062 An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log contents via executing a crafted command. [email protected] 5.3 0.14% 2024-01-13 2025-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence