PT-2018-9035 · Qnap · Qsync Central+1
Marcin Zieba
·
Published
2018-11-30
·
Updated
2018-12-26
·
CVE-2018-0716
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
QTS versions prior to 4.3.5
Qsync Central versions prior to 3.0.4
Description
A cross-site scripting issue allows remote attackers to inject Javascript code into the compromised application.
Recommendations
For QTS versions prior to 4.3.5, update to version 4.3.5 or later to resolve the issue.
For Qsync Central versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qts
Qsync Central