CVE-2017-7634: vulnerability in QNAP Media Streaming Add-On
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
Affected products
QNAP · QNAP Media Streaming Add-OnRelated CVEs — QNAP Media Streaming Add-On
In the same product, most dangerous first.