← Back

CVE-2018-19943

nvd nist
Published: Oct 28, 2020Modified: Nov 3, 2025CISA KEV

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

Affected (16)

Products: Qnap: Qts
1 product
Qts
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Qnap
Before 4.2.6
From 4.3.1.0013 to 4.3.3.1252
From 4.3.4 to 4.3.4.1282
From 4.3.6 to 4.3.6.1263
From 4.4.0 to 4.4.1.1261
From 4.4.2 to 4.4.2.1270
Version 4.2.6
Version 4.2.6 build_20170517
Version 4.2.6 build_20190322
Version 4.2.6 build_20190730
Version 4.2.6 build_20190921
Version 4.2.6 build_20191107
Version 4.2.6 build_20200109
Version 4.2.6 build_20200421
Version 4.2.6 build_20200611
Version 4.2.6 build_20200821

References (3)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.