Description
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Scores
CVSS v3
9.0
EPSS
0.0030
EPSS Percentile
52.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-80
CWE-79
CWE-749
Status
published
Products (2)
qnap/qes
2.1.1 (7 CPE variants)
qnap/qes
< 2.1.1
Published
Dec 24, 2020
Tracked Since
Feb 18, 2026