6.1

CVE-2021-44053

Reflected XSS

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.0.1986 build 20220324 and later QuTS hero h5.0.0.1986 build 20220324 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTScloud c5.0.1.1949 and later
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qnap ≫ Qts Version >= 5.0.0.1716 < 5.0.0.1986
Qnap ≫ Qts Version >= 4.3.3.0174 < 4.3.3.1945
Qnap ≫ Qts Version >= 4.3.4.0899 < 4.3.4.1976
Qnap ≫ Qts Version >= 4.3.6.0895 < 4.3.6.1965
Qnap ≫ Qts Version >= 4.4.0.0883 < 4.5.4.1991
Qnap ≫ Qts Version 4.2.6 Update build_20170517
Qnap ≫ Qts Version 4.2.6 Update build_20190322
Qnap ≫ Qts Version 4.2.6 Update build_20190730
Qnap ≫ Qts Version 4.2.6 Update build_20190921
Qnap ≫ Qts Version 4.2.6 Update build_20191107
Qnap ≫ Qts Version 4.2.6 Update build_20200109
Qnap ≫ Qts Version 4.2.6 Update build_20200421
Qnap ≫ Qts Version 4.2.6 Update build_20200611
Qnap ≫ Qts Version 4.2.6 Update build_20200821
Qnap ≫ Qts Version 4.2.6 Update build_20210327
Qnap ≫ Qts Version 4.2.6 Update build_20211215
Qnap ≫ Quts Hero Version < h4.5.4.1771
Qnap ≫ Quts Hero Version >= h5.0.0.1772 < h5.0.0.1986
Qnap ≫ Qutscloud Version < c5.0.1.1998
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.503
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
security@qnapsecurity.com.tw 5.7 2.1 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://www.qnap.com/en/security-advisory/qsa-22-16
Vendor Advisory