CVE-2018-0716: XSS
Cross-site scripting vulnerability in QTS 4.2.6 build 20180711, QTS 4.3.3: Qsync Central 3.0.2, QTS 4.3.4: Qsync Central 3.0.3, QTS 4.3.5: Qsync Central 3.0.4 and earlier versions could allow remote attackers to inject Javascript code in the compromised application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0716?
The severity of CVE-2018-0716 is classified as medium due to the potential for remote code execution via cross-site scripting.
How do I fix CVE-2018-0716?
To fix CVE-2018-0716, update affected QNAP QTS versions to the latest patched version as recommended by QNAP.
Which versions are affected by CVE-2018-0716?
CVE-2018-0716 affects QTS versions 4.2.6, 4.3.3, 4.3.4, and 4.3.5 of QNAP QTS and earlier.
What are the potential risks of CVE-2018-0716?
The potential risks of CVE-2018-0716 include unauthorized access and manipulation of user sessions through malicious JavaScript injection.
Is there a workaround for CVE-2018-0716 until I can update?
A temporary workaround for CVE-2018-0716 includes restricting access to Qsync Central until a patch is applied.