First published: Thu Jun 03 2021(Updated: )
A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Q\'center | <1.12.1012 | |
QNAP QTS | =4.5.3 | |
Qnap Q\'center | <1.10.1004 | |
QNAP QTS | =4.3.3 | |
QNAP QTS | =4.3.6 | |
QNAP QuTS hero | =h4.5.2 | |
QNAP QuTScloud | =c4.5.4 |
QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28807 is a post-authentication reflected XSS vulnerability that affects QNAP NAS running Q’center.
If exploited, CVE-2021-28807 allows remote attackers to inject malicious code into QNAP NAS running Q’center.
The severity of CVE-2021-28807 is high, with a CVSS score of 5.4.
Versions of Q’center up to 1.10.1004 are affected by CVE-2021-28807.
To fix CVE-2021-28807, update Q’center to version 1.12.1012 or later.