CVE-2019-7197

MEDIUM

QNAP QTS Admin Console - Stored Cross-Site Scripting

Title source: manual
STIX 2.1

Description

A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0031
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (5)
qnap/qts 4.2.6
qnap/qts 4.3.3
qnap/qts 4.3.4
qnap/qts 4.3.6
qnap/qts 4.4.1
Published Dec 04, 2019
Tracked Since Feb 18, 2026