PT-2022-10747 · Qnap · Qutscloud+2
Tony Martin
·
Published
2022-01-07
·
Updated
2022-01-14
·
CVE-2021-38674
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
QTS versions prior to 4.5.4.1787 build 20210910
QuTS hero versions prior to h4.5.4.1771 build 20210825
QuTScloud versions prior to c4.5.7.1864
Description
A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero, and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code.
Recommendations
For QTS versions prior to 4.5.4.1787 build 20210910, update to version 4.5.4.1787 build 20210910 or later.
For QuTS hero versions prior to h4.5.4.1771 build 20210825, update to version h4.5.4.1771 build 20210825 or later.
For QuTScloud versions prior to c4.5.7.1864, update to version c4.5.7.1864 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qts
Quts Hero
Qutscloud