← Back

CVE-2021-38681

nvd nist
Published: Nov 20, 2021Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.5
Source: NVD

Description

A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.

Affected (1)

Products: Qnap: Ragic Cloud Db
1 product
Ragic Cloud Db
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 3.7.0.1
Running on/withPlatform Versions
Qnap
Nas
All versions

References (2)

Source: security@qnapsecurity.com.tw
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.