We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later
No analysis available yet.
Vendor Solution
We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-54 |
|
Fri, 18 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later | |
| Title | QcalAgent | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-09-18T14:31:44.541Z
Reserved: 2024-02-20T09:36:58.211Z
Link: CVE-2024-27123
No data.
Status : Received
Published: 2026-09-18T07:16:48.117
Modified: 2026-09-18T15:17:03.710
Link: CVE-2024-27123
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')