PT-2020-15869 · Qnap · Quts Hero+1

Jan Hoff

·

Published

2020-12-10

·

Updated

2021-06-22

·

CVE-2020-2496

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions QTS versions prior to 4.5.1.1456 build 20201015 QuTS hero versions prior to h4.5.1.1472 build 20201031
Description If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station.
Recommendations For QTS versions prior to 4.5.1.1456 build 20201015, update to QTS 4.5.1.1456 build 20201015 or later. For QuTS hero versions prior to h4.5.1.1472 build 20201031, update to QuTS hero h4.5.1.1472 build 20201031 or later. As a temporary workaround, consider restricting access to File Station until a patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-2496

Affected Products

Qts
Quts Hero