CVE-2021-44053

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of QTS, QuTS hero and QuTScloud: QTS 4.5.4.1991 build 20220329 and later QTS 5.0.0.1986 build 20220324 and later QuTS hero h5.0.0.1986 build 20220324 and later QuTS hero h4.5.4.1971 build 20220310 and later QuTScloud c5.0.1.1949 and later
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
qnapCNA
5.7 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
VendorProductVersion
qnapqts
5.0.0.1716 ≤
𝑥
< 5.0.0.1986
qnapqts
4.3.3.0174 ≤
𝑥
< 4.3.3.1945
qnapqts
4.3.4.0899 ≤
𝑥
< 4.3.4.1976
qnapqts
4.3.6.0895 ≤
𝑥
< 4.3.6.1965
qnapqts
4.4.0.0883 ≤
𝑥
< 4.5.4.1991
qnapqts
4.2.6:build_20170517
qnapqts
4.2.6:build_20190322
qnapqts
4.2.6:build_20190730
qnapqts
4.2.6:build_20190921
qnapqts
4.2.6:build_20191107
qnapqts
4.2.6:build_20200109
qnapqts
4.2.6:build_20200421
qnapqts
4.2.6:build_20200611
qnapqts
4.2.6:build_20200821
qnapqts
4.2.6:build_20210327
qnapqts
4.2.6:build_20211215
𝑥
= Vulnerable software versions