Junglewise Threat Intelligence

CVE-2018-19953: QNAP NAS File Station Cross-Site Scripting Vulnerability

CVE-2018-19953 · Severity: critical · CVSS 6.1 · Exploited in the wild · Published 2022-05-24

Technologies: QNAP QTS, QNAP Network Attached Storage (NAS). Vendors: QNAP.

Executive brief

A cross-site scripting (XSS) vulnerability in QNAP NAS File Station allows remote attackers to inject malicious code into web pages. The vulnerability requires user interaction and affects multiple versions of the QTS operating system.

Affected products

  • QNAP QTS < 4.4.2.1231 build 20200302
  • QNAP QTS < 4.4.1.1201 build 20200130
  • QNAP QTS < 4.3.6.1218 build 20200214
  • QNAP QTS < 4.3.4.1190 build 20200107
  • QNAP QTS < 4.3.3.1161 build 20200109
  • QNAP QTS < 4.2.6 build 20200109
  • QNAP File Station

Timeline

  • 2020-10-28: disclosed: NVD Published Date
  • 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-01-07: patched: Fix released for QTS 4.3.4.1190
  • 2020-01-09: patched: Fix released for QTS 4.3.3.1161 and 4.2.6
  • 2020-01-30: patched: Fix released for QTS 4.4.1.1201
  • 2020-02-14: patched: Fix released for QTS 4.3.6.1218
  • 2020-03-02: patched: Fix released for QTS 4.4.2.1231

Related threats