Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-4590 | Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/nas-201805-16 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T16:18:40.800Z
Reserved: 2017-08-22T00:00:00
Link: CVE-2017-13072
No data.
Status : Modified
Published: 2018-06-21T13:29:00.273
Modified: 2024-11-21T03:10:54.440
Link: CVE-2017-13072
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD