Description
Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.qnap.com/zh-tw/security-advisory/nas-201804-27
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1040779
Scores
CVSS v3
6.1
EPSS
0.0023
EPSS Percentile
45.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (12)
qnap/qts
4.3.3.0514
qnap/qts
4.3.3.0546
qnap/qts
4.3.3.0570
qnap/qts
4.3.4.0516
qnap/qts
4.3.4.0526
qnap/qts
4.3.4.0551
qnap/qts
4.3.4.0557
qnap/qts
4.3.4.0561
qnap/qts
4.3.4.0569
qnap/qts
4.3.4.0593
... and 2 more
Published
Apr 30, 2018
Tracked Since
Feb 18, 2026