← Back to CVE List
Vulnerability Analysis

CVE-2018-19953

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

CISA KEV SSVC: Active Exploitation Cross-Site Scripting (XSS)
CVSS Base Score
6.1
MEDIUM
Exploitability:2.9
Impact Score:2.8
Temporal Score:-
EPSS:23.89%

Threat Intelligence Signals

CISA KEV
YES
KEV Date Added
2022-05-24
Ransomware Use
Known
KEV Due Date
2022-06-14
VulnCheck In-the-Wild
No
Nuclei Template
No
EPSS Score
23.894%
EPSS Percentile
97.6th pct
GitHub Severity
MODERATE
SSVC Exploitation
Active
SSVC Automatable
No
Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

Status-
Assigning Authority-
CVSS Version / Source-
Reserved-
Published-
Patch Date (date_public)-
Exploit DB Date-
First GitHub PoC Date-
Last Updated-
Time to Patch (Days to fix)-
Exploit Release Gap-
PoC Release Gap-
Exploit DB ReferencesNone identified

Affected Products & Versions

Vendor Product Affected Versions
No affected products specified.

References

No reference links found.

LINK COPIED TO CLIPBOARD