Description
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network.
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 20231128 and later
We have already fixed the vulnerability in the following versions:
QuTScloud c5.1.5.2651 and later
QTS 5.1.4.2596 build 20231128 and later
QuTS hero h5.1.4.2596 build 20231128 and later
No analysis available yet.
Remediation
Vendor Solution
We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-37190 | A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later |
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-11 |
|
History
Fri, 05 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap qts Qnap quts Hero Qnap qutscloud |
|
| CPEs | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:qts:5.1.4.2596:-:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:*:*:*:*:*:*:*:* cpe:2.3:o:qnap:quts_hero:h5.1.4.2596:-:*:*:*:*:*:* cpe:2.3:o:qnap:qutscloud:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Qnap
Qnap qts Qnap quts Hero Qnap qutscloud |
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-08-02T15:32:46.225Z
Reserved: 2023-05-16T10:44:49.055Z
Link: CVE-2023-32969
Updated: 2024-08-02T15:32:46.225Z
Status : Analyzed
Published: 2024-03-08T17:15:21.613
Modified: 2025-12-05T21:49:39.607
Link: CVE-2023-32969
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD