CVE-2018-19943
CVE-2018-19943
In short
A cross-site scripting (XSS) vulnerability in QNAP QTS allows attackers to inject malicious code that runs in users' browsers, potentially stealing data or taking control of their NAS device.
Technical detail
Reflected or stored XSS vulnerability in QNAP QTS web interface (CWE-79/80) allows unauthenticated or authenticated remote attackers to inject arbitrary JavaScript. Exploitation requires user interaction or direct access to vulnerable endpoints; successful exploitation impacts confidentiality and integrity of user sessions and stored data.
Summary generated and translated by AI from the official description.
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
QNAP Systems Inc. · QTSWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →