CVE-2021-34359Cross-site Scripting in Systems INC Proxy Server

Severity
5.4MEDIUMNVD
CNA6.9
EPSS
0.2%
top 55.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateFeb 26

Description

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5qnap_systems_inc/proxy_serverunspecified1.4.2 ( 2021/12/30 )

🔴Vulnerability Details

2
GHSA
GHSA-2cm8-2mh8-q729: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server2022-02-26
CVEList
Stored XSS Vulnerability in Proxy Server2022-02-25
CVE-2021-34359 — Cross-site Scripting | cvebase