If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code
Published Oct 28, 2020 ·Due Jun 14, 2022
6.1
MEDIUMCVSS 3.1
EPSS 28.77%
Description
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<4.2.6
- Version unspecifiedStatusaffectedConstraints<4.3.3.1161
- Version unspecifiedStatusaffectedConstraints<4.3.4.1190
- Version unspecifiedStatusaffectedConstraints<4.3.6.1218
- Version unspecifiedStatusaffectedConstraints<4.4.1.1201
- Version unspecifiedStatusaffectedConstraints<4.4.2.1231
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| QNAP Systems Inc. | QTS | n/a |
|
- < 4.2.6
- ≥ 4.3.1.0013 · < 4.3.3.1161
- ≥ 4.3.4 · < 4.3.4.1190
- ≥ 4.3.6 · < 4.3.6.1218
- ≥ 4.4.0 · < 4.4.1.1201
- ≥ 4.4.2 · < 4.4.2.1231
- 4.2.6
- 4.2.6
- 4.2.6
- 4.2.6
- 4.2.6
- 4.2.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Date Added
May 24, 2022
Patch Due
Jun 14, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Aug 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 28.77% (0.28771) | 98.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 23.89% (0.23894) | 97.54th | v5 (v2026.06.15) |
| Nov 21, 2025 | 31.52% (0.31524) | 96.58th | v4 (v2025.03.14) |
| Nov 18, 2025 | 12.83% (0.12832) | 93.37th | v4 (v2025.03.14) |
| Nov 4, 2025 | 31.52% (0.31524) | 96.56th | v4 (v2025.03.14) |
| Aug 13, 2025 | 34.49% (0.34489) | 96.84th | v4 (v2025.03.14) |
| May 28, 2025 | 39.21% (0.39209) | 97.09th | v4 (v2025.03.14) |
| Apr 28, 2025 | 41.45% (0.41449) | 97.19th | v4 (v2025.03.14) |
| Mar 30, 2025 | 38.72% (0.38718) | 96.96th | v4 (v2025.03.14) |
| Mar 29, 2025 | 53.67% (0.53666) | 97.08th | v4 (v2025.03.14) |
| Mar 17, 2025 | 38.72% (0.38718) | 96.92th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.38% (0.00379) | 73.17th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.38% (0.00379) | 72.19th | v3 (v2023.03.01) |
| Jun 4, 2023 | 0.38% (0.00376) | 68.82th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.37% (0.00370) | 68.27th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.05% (0.01055) | 50.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.05% (0.01055) | 48.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.05% (0.01055) | 27.52th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.52% (0.00523) | 12.55th | v1 |
| Jan 6, 2022 | 0.52% (0.00523) | 12.10th | v1 |
| Sep 1, 2021 | 0.52% (0.00523) | 32.27th | v1 |
| Apr 14, 2021 | 0.52% (0.00523) | 0.00th | v1 |
References (2)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19953 government-resourceUS Government Resource
- https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-19953 | government-resourceUS Government Resource | |
| https://www.qnap.com/zh-tw/security-advisory/qsa-20-01 | x_refsource_MISCVendor Advisory |
Change history (4)
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial
- CISA ADP
- SSVC technical impact changed from partial to
total partial → total
- SSVC technical impact changed from partial to
total
- CISA ADP
- SSVC technical impact changed from total to
partial total → partial
- SSVC technical impact changed from total to
partial