CVE-2021-34361: Reflected XSS Vulnerability in Proxy Server
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34361?
CVE-2021-34361 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Proxy Server.
How does CVE-2021-34361 work?
CVE-2021-34361 allows remote attackers to inject malicious code into QNAP devices through a cross-site scripting vulnerability.
What is the severity of CVE-2021-34361?
CVE-2021-34361 has a severity rating of medium, with a CVSS score of 6.1.
Which versions of Proxy Server are affected by CVE-2021-34361?
QNAP devices running Proxy Server versions up to 1.4.2 are affected by CVE-2021-34361.
How can I fix the CVE-2021-34361 vulnerability?
To fix the CVE-2021-34361 vulnerability, you should update Proxy Server to a version that is higher than 1.4.2, as recommended by QNAP.