PT-2021-17931 · Qnap · Quts Hero+4

Andrea Cappa

+1

·

Published

2021-06-03

·

Updated

2021-09-14

·

CVE-2021-28807

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: QNAP NAS running Q’center versions prior to Q’center v1.10.1004 QNAP NAS running Q’center versions prior to Q’center v1.12.1012
Description: A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code.
Recommendations: For QTS 4.5.3, update to Q’center v1.12.1012 or later. For QTS 4.3.6, update to Q’center v1.10.1004 or later. For QTS 4.3.3, update to Q’center v1.10.1004 or later. For QuTS hero h4.5.2, update to Q’center v1.12.1012 or later. For QuTScloud c4.5.4, update to Q’center v1.12.1012 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-28807

Affected Products

Qnap Nas
Qts
Q'Center
Quts Hero
Qutscloud