Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-4590 | Cross-site scripting (XSS) vulnerability in App Center in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and their earlier versions could allow remote attackers to inject Javascript code. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/nas-201805-16 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T16:18:40.800Z
Reserved: 2017-08-22T00:00:00.000Z
Link: CVE-2017-13072
No data.
Status : Modified
Published: 2018-06-21T13:29:00.273
Modified: 2024-11-21T03:10:54.440
Link: CVE-2017-13072
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD