First published: Thu Dec 24 2020(Updated: )
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap QES | <2.1.1 | |
Qnap QES | =2.1.1 | |
Qnap QES | =2.1.1-build_20200211 | |
Qnap QES | =2.1.1-build_20200303 | |
Qnap QES | =2.1.1-build_20200319 | |
Qnap QES | =2.1.1-build_20200424 | |
Qnap QES | =2.1.1-build_20200515 | |
Qnap QES | =2.1.1-build_20200811 |
QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2503 is a stored cross-site scripting vulnerability that can have a high impact if exploited.
To fix CVE-2020-2503, upgrade to QES version 2.1.1 Build 20201006 or later.
CVE-2020-2503 affects all QNAP QES versions prior to 2.1.1 Build 20201006.
If exploited, CVE-2020-2503 could allow remote attackers to inject malicious code into the File Station.
Yes, a patch to resolve CVE-2020-2503 is included in QES versions 2.1.1 Build 20201006 and later.