PT-2022-10342 · Qnap · Qnap Proxy Server

Tony Martin

·

Published

2022-02-25

·

Updated

2022-03-08

·

CVE-2021-34359

CVSS v3.1

6.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions QNAP Proxy Server versions prior to 1.4.2
Description A cross-site scripting (XSS) vulnerability has been reported to affect QNAP devices running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code.
Recommendations For QNAP Proxy Server versions prior to 1.4.2, update to Proxy Server 1.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the Proxy Server until a patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-34359

Affected Products

Qnap Proxy Server