First published: Thu Nov 11 2021(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qmailagent | <3.0.2 | |
QNAP NAS |
We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34357 is a cross-site scripting (XSS) vulnerability affecting QNAP devices running QmailAgent.
CVE-2021-34357 allows remote attackers to inject malicious code into QmailAgent, potentially leading to unauthorized access or data theft.
QNAP devices running QmailAgent versions up to and excluding 3.0.2 are affected by CVE-2021-34357.
Yes, QNAP has fixed the vulnerability in QmailAgent version 3.0.2 (released on 2021/08/25).
You can find more information about CVE-2021-34357 in the QNAP Security Advisory QSA-21-47, available at https://www.qnap.com/en/security-advisory/qsa-21-47.