First published: Wed Oct 28 2020(Updated: )
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP QTS | <4.2.6 | |
QNAP QTS | >=4.3.1.0013<4.3.3.1161 | |
QNAP QTS | >=4.3.4<4.3.4.1190 | |
QNAP QTS | >=4.3.6<4.3.6.1218 | |
QNAP QTS | >=4.4.0<4.4.1.1201 | |
QNAP QTS | >=4.4.2<4.4.2.1231 | |
QNAP QTS | =4.2.6 | |
QNAP QTS | =4.2.6-build_20170517 | |
QNAP QTS | =4.2.6-build_20190322 | |
QNAP QTS | =4.2.6-build_20190730 | |
QNAP QTS | =4.2.6-build_20190921 | |
QNAP QTS | =4.2.6-build_20191107 | |
QNAP Network Attached Storage (NAS) | ||
<4.2.6 | ||
>=4.3.1.0013<4.3.3.1161 | ||
>=4.3.4<4.3.4.1190 | ||
>=4.3.6<4.3.6.1218 | ||
>=4.4.0<4.4.1.1201 | ||
>=4.4.2<4.4.2.1231 | ||
=4.2.6 | ||
=4.2.6-build_20170517 | ||
=4.2.6-build_20190322 | ||
=4.2.6-build_20190730 | ||
=4.2.6-build_20190921 | ||
=4.2.6-build_20191107 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19953 is a cross-site scripting vulnerability in QNAP NAS File Station.
The CVE-2018-19953 vulnerability can be exploited by remote attackers injecting malicious code.
CVE-2018-19953 has a severity level of medium.
QTS versions up to 4.4.2.1231, 4.4.1.1201, 4.3.6.1218, and 4.3.4.1190 are affected by CVE-2018-19953.
To fix the CVE-2018-19953 vulnerability, update your QTS to version 4.4.2.1231, 4.4.1.1201, 4.3.6.1218, or 4.3.4.1190.