CVE-2023-23357: QuLog Center
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later QuLog Center 1.4.1.691 ( 2023/03/01 ) and later QuLog Center 1.3.1.645 ( 2023/02/22 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23357?
CVE-2023-23357 is characterized as a critical vulnerability due to its potential to allow remote attackers to bypass security mechanisms.
How do I fix CVE-2023-23357?
To fix CVE-2023-23357, you should update the affected QNAP QuLog Center to the latest version provided by QNAP.
Which QNAP software versions are affected by CVE-2023-23357?
CVE-2023-23357 affects QNAP QuLog Center versions prior to 1.5.0.738, 1.4.1.691, and 1.3.1.645.
Can CVE-2023-23357 be exploited remotely?
Yes, CVE-2023-23357 can be exploited remotely by attackers who have gained administrator access.
What type of vulnerability is CVE-2023-23357?
CVE-2023-23357 is a cross-site scripting (XSS) vulnerability that affects QNAP operating systems.