6.1
CVSSv3

CVE-2023-23372

Published: 08/12/2023 Updated: 12/12/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QTS 5.0.1.2425 build 20230609 and later QTS 5.1.0.2444 build 20230629 and later QTS 4.5.4.2467 build 20230718 and later QuTS hero h5.1.0.2424 build 20230609 and later QuTS hero h5.0.1.2515 build 20230907 and later QuTS hero h4.5.4.2476 build 20230728 and later

Vulnerable Product Search on Vulmon Subscribe to Product

qnap qts 5.1.0.2348

qnap qts 5.1.0.2418

qnap qts 5.1.0.2399

qnap qts 5.0.1.2346

qnap qts 5.0.1.2277

qnap qts 5.0.1.2248

qnap qts 5.0.1.2234

qnap qts 5.0.1.2194

qnap qts 5.0.1.2173

qnap qts 5.0.1.2145

qnap qts 5.0.1.2137

qnap qts 5.0.1.2131

qnap qts 5.0.1.2079

qnap qts 5.0.1.2034

qnap qts 5.0.1.2376

qnap qts 4.5.4.2280

qnap qts 4.5.4.2117

qnap qts 4.5.4.2012

qnap qts 4.5.4.1931

qnap qts 4.5.4.1800

qnap qts 4.5.4.1787

qnap qts 4.5.4.1741

qnap qts 4.5.4.1723

qnap qts 4.5.4.1715

qnap qts 4.5.4.1892

qnap qts 4.5.4.2374

qnap quts hero h5.1.0.2409

qnap quts hero h5.0.1.2348

qnap quts hero h5.0.1.2277

qnap quts hero h5.0.1.2269

qnap quts hero h5.0.1.2248

qnap quts hero h5.0.1.2192

qnap quts hero h5.0.1.2045

qnap quts hero h5.0.1.2376

qnap quts hero h4.5.4.2272

qnap quts hero h4.5.4.2217

qnap quts hero h4.5.4.2138

qnap quts hero h4.5.4.2052

qnap quts hero h4.5.4.1991

qnap quts hero h4.5.4.1971

qnap quts hero h4.5.4.1951

qnap quts hero h4.5.4.1892

qnap quts hero h4.5.4.1848

qnap quts hero h4.5.4.1813

qnap quts hero h4.5.4.1800

qnap quts hero h4.5.4.1771

qnap quts hero h4.5.4.2374