CVE-2020-2503: Stored cross-site scripting vulnerability in QES
Published Dec 24, 2020
·Updated
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Affected Software
8 affected components
QNAP QES<2.1.1
QNAP QES=2.1.1
QNAP QES=2.1.1-build_20200211
QNAP QES=2.1.1-build_20200303
QNAP QES=2.1.1-build_20200319
QNAP QES=2.1.1-build_20200424
QNAP QES=2.1.1-build_20200515
QNAP QES=2.1.1-build_20200811
Remediation
Information
QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Event History
Dec 24, 2020
CVE Published
via MITRE·01:39 AM
Data Sourced
via MITRE·01:39 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-2503?
CVE-2020-2503 is a stored cross-site scripting vulnerability that can have a high impact if exploited.
2
How do I fix CVE-2020-2503?
To fix CVE-2020-2503, upgrade to QES version 2.1.1 Build 20201006 or later.
3
What software is affected by CVE-2020-2503?
CVE-2020-2503 affects all QNAP QES versions prior to 2.1.1 Build 20201006.
4
What could happen if CVE-2020-2503 is exploited?
If exploited, CVE-2020-2503 could allow remote attackers to inject malicious code into the File Station.
5
Is there a patch available for CVE-2020-2503?
Yes, a patch to resolve CVE-2020-2503 is included in QES versions 2.1.1 Build 20201006 and later.