CVE-2018-19943
בינונית 5.4 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- QNAP NAS File Station Cross-Site Scripting Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 18% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-79, CWE-80
מוצרים מושפעים
qnap: qts
קישורים
- https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource