CVE-2018-19953: QNAP NAS File Station Cross-Site Scripting Vulnerability
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Other sources
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.4.2.1231 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.4.1.1201 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.6.1218 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.4.1190 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.3.3.1161 - Upgrade
Upgrade
QNAP NAS File Station (QTS)to a version that resolves this vulnerability.Fixed in 4.2.6
Event History
Frequently Asked Questions
What is CVE-2018-19953?
CVE-2018-19953 is a cross-site scripting vulnerability in QNAP NAS File Station.
How can the CVE-2018-19953 vulnerability be exploited?
The CVE-2018-19953 vulnerability can be exploited by remote attackers injecting malicious code.
What is the severity level of CVE-2018-19953?
CVE-2018-19953 has a severity level of medium.
Which versions of QTS are affected by CVE-2018-19953?
QTS versions up to 4.4.2.1231, 4.4.1.1201, 4.3.6.1218, and 4.3.4.1190 are affected by CVE-2018-19953.
How can I fix the CVE-2018-19953 vulnerability?
To fix the CVE-2018-19953 vulnerability, update your QTS to version 4.4.2.1231, 4.4.1.1201, 4.3.6.1218, or 4.3.4.1190.