CVE-2020-2503

CRITICAL

Qnap Qes < 2.1.1 - Basic XSS

Title source: rule
STIX 2.1

Description

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Scores

CVSS v3 9.0
EPSS 0.0030
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-80 CWE-79 CWE-749
Status published
Products (2)
qnap/qes 2.1.1 (7 CPE variants)
qnap/qes < 2.1.1
Published Dec 24, 2020
Tracked Since Feb 18, 2026