PT-2021-7638 · Qnap+1 · Qnap Nas+1

Published

2021-11-20

·

Updated

2023-01-17

·

CVE-2021-38681

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions QNAP NAS running Ragic Cloud DB (affected versions not specified)
Description A reflected cross-site scripting (XSS) vulnerability has been reported, allowing remote attackers to inject malicious code if exploited. The vulnerability exists due to inadequate protection of the web page structure. QNAP has disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-00605
CVE-2021-38681

Affected Products

Qnap Nas
Ragic Cloud Db