CVE-2017-7634: XSS
Cross-site scripting (XSS) vulnerability in QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to inject arbitrary web script or HTML. The injected code will only be triggered by a crafted link, not the normal page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7634?
CVE-2017-7634 is a cross-site scripting (XSS) vulnerability found in the QNAP NAS application Media Streaming add-on.
How does CVE-2017-7634 affect QNAP NAS?
CVE-2017-7634 allows remote attackers to inject arbitrary web script or HTML into the QNAP NAS application Media Streaming add-on.
Which versions of the QNAP NAS Media Streaming add-on are affected by CVE-2017-7634?
Versions 421.1.0.2, 430.1.2.0, and earlier of the QNAP NAS Media Streaming add-on are affected by CVE-2017-7634.
How can CVE-2017-7634 be exploited?
CVE-2017-7634 can be exploited by crafting a specific link that triggers the injected malicious code.
Is the QNAP QTS affected by CVE-2017-7634?
No, the QNAP QTS operating system is not vulnerable to CVE-2017-7634.