CVE-2018-0711

MEDIUM

QNAP QTS - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1040779

Scores

CVSS v3 6.1
EPSS 0.0023
EPSS Percentile 45.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (12)
qnap/qts 4.3.3.0514
qnap/qts 4.3.3.0546
qnap/qts 4.3.3.0570
qnap/qts 4.3.4.0516
qnap/qts 4.3.4.0526
qnap/qts 4.3.4.0551
qnap/qts 4.3.4.0557
qnap/qts 4.3.4.0561
qnap/qts 4.3.4.0569
qnap/qts 4.3.4.0593
... and 2 more
Published Apr 30, 2018
Tracked Since Feb 18, 2026