CVE-2017-7636: XSS
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7636?
CVE-2017-7636 is a cross-site scripting (XSS) vulnerability in the QNAP NAS application Proxy Server through version 1.2.0 that allows remote attackers to inject arbitrary web script or HTML.
How severe is CVE-2017-7636?
CVE-2017-7636 has a severity rating of 6.1 (medium).
Which software version is affected by CVE-2017-7636?
Versions up to and excluding 1.3.0 of Qnap Nas Proxy Server are affected by CVE-2017-7636.
How can I fix CVE-2017-7636?
To fix CVE-2017-7636, you should update Qnap Nas Proxy Server to version 1.3.0 or newer.
Are there any references related to CVE-2017-7636?
Yes, you can find more information about CVE-2017-7636 at the following sources: [SecurityTracker](http://www.securitytracker.com/id/1041025) and [QNAP Security Advisory](https://www.qnap.com/en/security-advisory/nas-201806-01).