CVE-2017-7632

MEDIUM

QNAP QTS - Cross-Site Scripting in File Station

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to inject arbitrary web script or HTML.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0025
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
qnap/qts 4.2.6
qnap/qts 4.3.3
Published Mar 27, 2018
Tracked Since Feb 18, 2026