CVE-2018-19953

CVE Published 2020-10-28
Related CWE(s) CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Related Vendor(s) qnap
Related Product(s) qts
Exploitation Reported (CISA KEV) 2022-05-24
CVSS 3 Base Score 6.1 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References