Description
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
No analysis available yet.
Remediation
Vendor Workaround
QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. To secure your device, we recommend uninstalling Ragic Cloud DB until a security patch is available.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-25120 | A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-21-48 |
|
History
No history.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T22:30:22.100Z
Reserved: 2021-08-13T00:00:00.000Z
Link: CVE-2021-38681
No data.
Status : Modified
Published: 2021-11-20T01:15:08.303
Modified: 2024-11-21T06:17:53.187
Link: CVE-2021-38681
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD