← Back

CVE-2018-0711

nvd nist
Published: Apr 30, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

Affected (12)

Products: Qnap: Qts
1 product
Qts
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Version 4.3.3.0514
Version 4.3.3.0546
Version 4.3.3.0570
Version 4.3.4.0516
Version 4.3.4.0526
Version 4.3.4.0551
Version 4.3.4.0557
Version 4.3.4.0561
Version 4.3.4.0569
Version 4.3.4.0593
Version 4.3.4.0597
Version 4.3.4.0604

References (4)

Source: security@qnapsecurity.com.tw
Third Party AdvisoryVDB Entry
Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.