First published: Tue Jun 05 2018(Updated: )
Cross-site scripting (XSS) vulnerability in QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to inject arbitrary web script or HTML.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Nas Proxy Server | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7636 is a cross-site scripting (XSS) vulnerability in the QNAP NAS application Proxy Server through version 1.2.0 that allows remote attackers to inject arbitrary web script or HTML.
CVE-2017-7636 has a severity rating of 6.1 (medium).
Versions up to and excluding 1.3.0 of Qnap Nas Proxy Server are affected by CVE-2017-7636.
To fix CVE-2017-7636, you should update Qnap Nas Proxy Server to version 1.3.0 or newer.
Yes, you can find more information about CVE-2017-7636 at the following sources: [SecurityTracker](http://www.securitytracker.com/id/1041025) and [QNAP Security Advisory](https://www.qnap.com/en/security-advisory/nas-201806-01).