CVE-2021-34357: Reflected XSS Vulnerability in QmailAgent
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34357?
CVE-2021-34357 is a cross-site scripting (XSS) vulnerability affecting QNAP devices running QmailAgent.
How does CVE-2021-34357 impact QNAP devices?
CVE-2021-34357 allows remote attackers to inject malicious code into QmailAgent, potentially leading to unauthorized access or data theft.
Which QNAP devices are affected by CVE-2021-34357?
QNAP devices running QmailAgent versions up to and excluding 3.0.2 are affected by CVE-2021-34357.
Has QNAP released a fix for CVE-2021-34357?
Yes, QNAP has fixed the vulnerability in QmailAgent version 3.0.2 (released on 2021/08/25).
Where can I find more information about CVE-2021-34357?
You can find more information about CVE-2021-34357 in the QNAP Security Advisory QSA-21-47, available at https://www.qnap.com/en/security-advisory/qsa-21-47.