← Back

CVE-2023-23354

nvd nist
Published: Dec 19, 2024Modified: Jan 20, 2026

JSON object

Loading...
8.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Exploitability: 2.3 / Impact: 5.8
Source: NVD

Description

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later QuLog Center 1.4.1.691 ( 2023/03/01 ) and later QuLog Center 1.3.1.645 ( 2023/02/22 ) and later

Affected (3)

Products: Qnap: Qulog Center
1 product
Qulog Center
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 1.5.0.738
Running on/withPlatform Versions
Qnap
Qts
Version 5.0.1
Qnap
Quts Hero
Version h5.0.1
Configuration B
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 1.3.1.645
Running on/withPlatform Versions
Qnap
Qts
Version 4.5.4
Qnap
Quts Hero
Version h4.5.4
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.4.1.691
Running on/withPlatform Versions
Qnap
Qutscloud
Version c5.0.1

References (1)

Source: security@qnapsecurity.com.tw
Vendor Advisory

Timeline

No history available yet.