A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2021-25120 | A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. |
Fixes
Solution
No solution given by the vendor.
Workaround
QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. To secure your device, we recommend uninstalling Ragic Cloud DB until a security patch is available.
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-21-48 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-09-16T22:30:22.100Z
Reserved: 2021-08-13T00:00:00
Link: CVE-2021-38681

No data.

Status : Modified
Published: 2021-11-20T01:15:08.303
Modified: 2024-11-21T06:17:53.187
Link: CVE-2021-38681

No data.

No data.