CVE-2018-0719: Security Advisory for Vulnerabilities in QTS
Cross-site Scripting (XSS) vulnerability in NAS devices of QNAP Systems Inc. QTS allows attackers to inject javascript. This issue affects: QNAP Systems Inc. QTS version 4.2.6 and prior versions on build 20180711; version 4.3.3 and prior versions on build 20180725; version 4.3.4 and prior versions on build 20180710.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0719?
CVE-2018-0719 has a severity rating of high due to its potential for cross-site scripting attacks.
Who is affected by CVE-2018-0719?
CVE-2018-0719 affects QNAP QTS versions 4.2.6 and older, as well as certain builds of 4.3.3 and 4.3.4.
How can I fix CVE-2018-0719?
To fix CVE-2018-0719, upgrade your QNAP QTS to the latest patched version provided by QNAP.
What type of vulnerability is CVE-2018-0719?
CVE-2018-0719 is a cross-site scripting (XSS) vulnerability.
What are the consequences of not addressing CVE-2018-0719?
Not addressing CVE-2018-0719 could allow attackers to execute malicious JavaScript in the context of a victim's browser.