// For flags

CVE-2018-19943

QNAP NAS File Station Cross-Site Scripting Vulnerability

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

Si es explotada esta vulnerabilidad de tipo cross-site scripting podría permitir a atacantes remotos inyectar código malicioso. QNAP ya ha corregido estos problemas en las siguientes versiones de QTS. QTS versión 4.4.2.1270 build 20200410 y posterior a QTS versión 4.4.1.1261 build 20200330 y posterior a QTS versión 4.3.6.1263 build 20200330 y posterior a QTS versión 4.3.4.1282 build 20200408 y posterior a QTS versión 4.3.3.1252 build 20200409 y posterior a QTS versión 4.2.6 build 20200421 y posterior

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

*Credits: Independent Security Evaluators
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-12-07 CVE Reserved
  • 2020-10-28 CVE Published
  • 2022-05-24 Exploited in Wild
  • 2022-06-14 KEV Due Date
  • 2023-03-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- First Exploit
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
< 4.2.6
Search vendor "Qnap" for product "Qts" and version " < 4.2.6"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.3.1.0013 < 4.3.3.1252
Search vendor "Qnap" for product "Qts" and version " >= 4.3.1.0013 < 4.3.3.1252"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.3.4 < 4.3.4.1282
Search vendor "Qnap" for product "Qts" and version " >= 4.3.4 < 4.3.4.1282"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.3.6 < 4.3.6.1263
Search vendor "Qnap" for product "Qts" and version " >= 4.3.6 < 4.3.6.1263"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.4.0 < 4.4.1.1261
Search vendor "Qnap" for product "Qts" and version " >= 4.4.0 < 4.4.1.1261"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
>= 4.4.2 < 4.4.2.1270
Search vendor "Qnap" for product "Qts" and version " >= 4.4.2 < 4.4.2.1270"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
-
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20170517
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20190322
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20190730
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20190921
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20191107
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20200109
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20200421
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20200611
Affected
Qnap
Search vendor "Qnap"
Qts
Search vendor "Qnap" for product "Qts"
4.2.6
Search vendor "Qnap" for product "Qts" and version "4.2.6"
build_20200821
Affected