CVE-2017-7631

MEDIUM

QNAP QTS 4.2.6 build 20171026 and earlier - Cross-Site Scripting in File Station Share Link Function

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 53.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
qnap/qts 4.2.6
qnap/qts 4.3.3
Published Mar 27, 2018
Tracked Since Feb 18, 2026