6.1

CVE-2018-19953

Warnung
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version < 4.2.6
Qnap ≫ Qts Version >= 4.3.1.0013 < 4.3.3.1161
Qnap ≫ Qts Version >= 4.3.4 < 4.3.4.1190
Qnap ≫ Qts Version >= 4.3.6 < 4.3.6.1218
Qnap ≫ Qts Version >= 4.4.0 < 4.4.1.1201
Qnap ≫ Qts Version >= 4.4.2 < 4.4.2.1231
Qnap ≫ Qts Version 4.2.6 Update -
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107

24.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

QNAP NAS File Station Cross-Site Scripting Vulnerability

Schwachstelle

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 23.89% 0.975
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CISA-ADP 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.

https://www.qnap.com/zh-tw/security-advisory/qsa-20-01
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19953
US Government Resource