[CVE-2018-19943] QNAP NAS File Station Cross-Site Scripting Vulnerability

SecurityDesk
2022.05.24 00:00 조회 14

CISA KEV 정보

취약점명QNAP NAS File Station Cross-Site Scripting Vulnerability
설명A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
조치사항Apply updates per vendor instructions.
랜섬웨어 캠페인 악용Known
CWECWE-79 | CWE-80
등록일 (KEV)2022-05-24
조치 기한2022-06-14
추가 참고https://nvd.nist.gov/vuln/detail/CVE-2018-19943

NVD 상세 정보

CVSS v3.1: 8.0 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS v2.0: 3.5 AV:N/AC:M/Au:S/C:N/I:P/A:N

설명: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CWE: CWE-79 | CWE-80 | CWE-79

참조

This product uses the NVD API but is not endorsed or certified by the NVD.



바로 가기

IT 도구 서랍

→ Unix: 2025-01-15T09:30:00
→ 날짜: 1736934600

→ ASCII: ABC
→ 문자: 65 66 67

ASCII 코드표 — 클릭하면 입력란에 추가

DecHex약어설명
DecHex문자
DecHex문자

→ 유니코드: 홍길동
→ 문자: \ud64d\uae38\ub3d9