← Back to CVE List
Vulnerability Intelligence Report
QNAP NAS File Station Cross-Site Scripting Vulnerability

CVE-2018-19943

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

CISA KEV SSVC: Active Exploitation Cross-Site Scripting (XSS)
CVSS Base Score
8.0
HIGH
Exploitability:1.3
Impact Score:6.1
EPSS Probability:17.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-79 ↗CWE-79 Cross-site Scripting (XSS)
CWE-80 ↗CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Affected Products & Versions

Vendor Product Affected Versions
QNAP Systems Inc. QTS unspecified < 4.4.2.1270 (affected)
QNAP Systems Inc. QTS unspecified < 4.4.1.1261 (affected), unspecified < 4.3.6.1263 (affected)
QNAP Systems Inc. QTS unspecified < 4.3.4.1282 (affected)
QNAP Systems Inc. QTS unspecified < 4.3.3.1252 (affected)
QNAP Systems Inc. QTS unspecified < 4.2.6 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
17.705%
Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityQNAP Systems, Inc. · Vendor · Taiwan
Reserved2018-12-07T00:00:00
Published2020-10-28T17:55:18
Last Updated2026-08-13T03:55:39

LINK COPIED TO CLIPBOARD