CVE-2017-13072

MEDIUM

QNAP QTS - Cross-Site Scripting in App Center

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.qnap.com/en/security-advisory/nas-201805-16

Scores

CVSS v3 6.1
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
qnap/qts 4.2.6
qnap/qts 4.3.3
qnap/qts 4.3.4
Published Jun 21, 2018
Tracked Since Feb 18, 2026