CVE-2019-7197: XSS
Published Dec 4, 2019
·Updated
A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.
Affected Software
5 affected components
QNAP QTS=4.2.6
QNAP QTS=4.3.3
QNAP QTS=4.3.4
QNAP QTS=4.3.6
QNAP QTS=4.4.1
Event History
Dec 4, 2019
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-7197?
The severity of CVE-2019-7197 is high due to its potential to allow stored XSS attacks on the administrator console.
2
How do I fix CVE-2019-7197?
To fix CVE-2019-7197, you should update QTS to the latest version recommended by QNAP.
3
Which versions of QTS are affected by CVE-2019-7197?
CVE-2019-7197 affects QTS versions 4.2.6, 4.3.3, 4.3.4, 4.3.6, and 4.4.1.
4
What type of vulnerability is CVE-2019-7197?
CVE-2019-7197 is a stored cross-site scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2019-7197?
An attacker can exploit CVE-2019-7197 to inject and execute scripts on the administrator console.