First published: Wed Sep 19 2018(Updated: )
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | =4.2.6 | |
QNAP QTS | =4.3.3 | |
QNAP QTS | =4.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0719 has a severity rating of high due to its potential for cross-site scripting attacks.
CVE-2018-0719 affects QNAP QTS versions 4.2.6 and older, as well as certain builds of 4.3.3 and 4.3.4.
To fix CVE-2018-0719, upgrade your QNAP QTS to the latest patched version provided by QNAP.
CVE-2018-0719 is a cross-site scripting (XSS) vulnerability.
Not addressing CVE-2018-0719 could allow attackers to execute malicious JavaScript in the context of a victim's browser.