CVE-2021-34359: Stored XSS Vulnerability in Proxy Server
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34359?
CVE-2021-34359 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Proxy Server.
How does CVE-2021-34359 affect QNAP devices?
If exploited, CVE-2021-34359 allows remote attackers to inject malicious code into QNAP devices running Proxy Server.
Which versions of Proxy Server are affected by CVE-2021-34359?
Versions of Proxy Server up to and excluding 1.4.2 are affected by CVE-2021-34359.
Has this vulnerability been fixed?
Yes, this vulnerability has been fixed in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2.
What is the severity of CVE-2021-34359?
CVE-2021-34359 has a severity rating of medium, with a CVSS score of 5.4.