Описание
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.923 ( 2025/08/27 ) and later
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 1.8.0.872 (включая) до 1.8.2.923 (исключая)
cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00079
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.8
github
3 месяца назад
A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QuLog Center 1.8.2.923 ( 2025/08/27 ) and later
EPSS
Процентиль: 24%
0.00079
Низкий
4.8 Medium
CVSS3
Дефекты
CWE-79