First published: Fri Jan 14 2022(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QcalAgent. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Qcalagent | <1.1.7 |
We have already fixed this vulnerability in the following versions of QcalAgent: QcalAgent 1.1.7 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-38677.
The severity rating of CVE-2021-38677 is medium, with a severity value of 6.1.
If exploited, this vulnerability allows remote attackers to inject malicious code into the affected device.
Versions of QcalAgent up to and excluding 1.1.7 are affected by CVE-2021-38677.
To fix the vulnerability, update QcalAgent to version 1.1.7 or later.