PT-2021-7638 · Qnap+1 · Qnap Nas+1
Published
2021-11-20
·
Updated
2023-01-17
·
CVE-2021-38681
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
QNAP NAS running Ragic Cloud DB (affected versions not specified)
Description
A reflected cross-site scripting (XSS) vulnerability has been reported, allowing remote attackers to inject malicious code if exploited. The vulnerability exists due to inadequate protection of the web page structure. QNAP has disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnap Nas
Ragic Cloud Db