CVE-2021-34361

Severity
6.1MEDIUM
EPSS
0.4%
top 42.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 25
Latest updateFeb 26

Description

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.6 | Impact: 3.6

Affected Packages2 packages

CVEListV5qnap_systems_inc./proxy_serverunspecified1.4.2 ( 2021/12/30 )

🔴Vulnerability Details

2
GHSA
GHSA-mf68-m5mw-75xq: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server2022-02-26
CVEList
Reflected XSS Vulnerability in Proxy Server2022-02-25