Description
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QuLog Center 1.5.0.738 ( 2023/03/06 ) and later QuLog Center 1.4.1.691 ( 2023/03/01 ) and later QuLog Center 1.3.1.645 ( 2023/02/22 ) and later
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- QNAP Systems Inc. / QuLog Center1.5.x.x – 1.5.0.738 ( 2023/03/06 )
- QNAP Systems Inc. / QuLog Center1.4.x.x – 1.4.1.691 ( 2023/03/01 )
- QNAP Systems Inc. / QuLog Center1.3.x.x – 1.3.1.645 ( 2023/02/22 )