Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-556x-fx4f-2hgg

Опубликовано: 29 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 4.8

Описание

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.

We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.

We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later

EPSS

Процентиль: 32%
0.00123
Низкий

7.1 High

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
5 месяцев назад

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later

EPSS

Процентиль: 32%
0.00123
Низкий

7.1 High

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-79