A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-21-48 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: qnap
Published: 2021-11-20T01:05:12.456318Z
Updated: 2024-09-16T22:30:22.100Z
Reserved: 2021-08-13T00:00:00
Link: CVE-2021-38681
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-20T01:15:08.303
Modified: 2024-11-21T06:17:53.187
Link: CVE-2021-38681
Redhat
No data.