PT-2021-17931 · Qnap · Quts Hero+4
Andrea Cappa
+1
·
Published
2021-06-03
·
Updated
2021-09-14
·
CVE-2021-28807
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
QNAP NAS running Q’center versions prior to Q’center v1.10.1004
QNAP NAS running Q’center versions prior to Q’center v1.12.1012
Description:
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code.
Recommendations:
For QTS 4.5.3, update to Q’center v1.12.1012 or later.
For QTS 4.3.6, update to Q’center v1.10.1004 or later.
For QTS 4.3.3, update to Q’center v1.10.1004 or later.
For QuTS hero h4.5.2, update to Q’center v1.12.1012 or later.
For QuTScloud c4.5.4, update to Q’center v1.12.1012 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnap Nas
Qts
Q'Center
Quts Hero
Qutscloud