Vulnerability Intelligence Report
QNAP NAS File Station Cross-Site Scripting Vulnerability
CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later
CISA KEV
SSVC: Active Exploitation
Cross-Site Scripting (XSS)
CVSS Base Score
8.0
HIGH
Exploitability:1.3
Impact Score:6.1
EPSS Probability:17.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-79 ↗CWE-79 Cross-site Scripting (XSS)
CWE-80 ↗CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| QNAP Systems Inc. | QTS | unspecified < 4.4.2.1270 (affected) |
| QNAP Systems Inc. | QTS | unspecified < 4.4.1.1261 (affected), unspecified < 4.3.6.1263 (affected) |
| QNAP Systems Inc. | QTS | unspecified < 4.3.4.1282 (affected) |
| QNAP Systems Inc. | QTS | unspecified < 4.3.3.1252 (affected) |
| QNAP Systems Inc. | QTS | unspecified < 4.2.6 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
EPSS Score
17.705%
GitHub Advisory
Vulnerability Class
Cross-Site Scripting (XSS)
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | QNAP Systems, Inc. · Vendor · Taiwan |
| Reserved | 2018-12-07T00:00:00 |
| Published | 2020-10-28T17:55:18 |
| Last Updated | 2026-08-13T03:55:39 |
Community Chatter & Buzz