← Back

CVE-2021-28807

nvd nist
Published: Jun 3, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A post-authentication reflected XSS vulnerability has been reported to affect QNAP NAS running Q’center. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already fixed this vulnerability in the following versions of Q’center: QTS 4.5.3: Q’center v1.12.1012 and later QTS 4.3.6: Q’center v1.10.1004 and later QTS 4.3.3: Q’center v1.10.1004 and later QuTS hero h4.5.2: Q’center v1.12.1012 and later QuTScloud c4.5.4: Q’center v1.12.1012 and later

Affected (2)

Products: Qnap: Q'center
1 product
Q'center
Configuration A
1 platform
Running on/withPlatform Versions
Qnap
Qts
Version 4.5.3
Configuration B
1 platform
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.3
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.10.1004
Running on/withPlatform Versions
Qnap
Qts
Version 4.3.6
Configuration D
1 platform
Running on/withPlatform Versions
Qnap
Quts Hero
Version h4.5.2
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12.1012
Running on/withPlatform Versions
Qnap
Qutscloud
Version c4.5.4

References (6)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: security@qnapsecurity.com.tw
ExploitThird Party Advisory
Source: security@qnapsecurity.com.tw
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.