CVE-2020-36194Cross-site Scripting in Systems INC QTS

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 45.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateMay 24

Description

An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, this vulnerability allows attackers to inject malicious code. This issue affects: QNAP Systems Inc. QTS versions prior to 4.5.2.1566 Build 20210202. QNAP Systems Inc. QuTS hero versions prior to h4.5.2.1638 build 20210414. This issue does not affect: QNAP Systems Inc. QTS 4.5.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

CVEListV5qnap_systems_inc/quts_herounspecifiedh4.5.2.1638 build 20210414
NVDqnap/quts_hero< h4.5.2.1638
CVEListV5qnap_systems_inc/qtsunspecified4.5.2.1566 Build 20210202
NVDqnap/qts< 4.5.2.1566

🔴Vulnerability Details

2
GHSA
GHSA-x4ff-r9rc-hrwg: An XSS vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero2022-05-24
CVEList
XSS Vulnerability in QTS and QuTS heroCommand Injection Vulnerabilities in QTS and QuTS hero2021-07-01
CVE-2020-36194 — Cross-site Scripting | cvebase