Back

MEDIUM KEV Used in ransomware campaigns

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code

Published Oct 28, 2020 ·Due Jun 14, 2022

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (4)
  1. CISA ADP
    • SSVC technical impact changed from partial to total
  2. CISA ADP
    • SSVC technical impact changed from total to partial
  3. CISA ADP
    • SSVC technical impact changed from partial to total
  4. CISA ADP
    • SSVC technical impact changed from total to partial
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner qnap
Published Oct 28, 2020
Updated Oct 1, 2026
Reserved Dec 7, 2018
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a