Junglewise Threat Intelligence

CVE-2024-27123: QNAP QcalAgent cross-site scripting

CVE-2024-27123 · Severity: info · Published 2026-09-18

Vendors: QNAP.

Executive brief

QcalAgent is a calendar application used to manage schedules and events. A cross-site scripting (XSS) vulnerability allows local attackers to inject malicious scripts that could bypass security controls or access sensitive application data.

Technical details

A cross-site scripting (XSS) vulnerability exists in QcalAgent that permits local attackers to inject and execute arbitrary client-side scripts. The attack vector requires local access to the affected system. Successful exploitation can lead to bypassing security mechanisms or unauthorized access to application data. The vulnerability has been patched in QcalAgent version 1.1.9 and later.

Affected products

  • QNAP QcalAgent before 1.1.9

Timeline

  • 2024-09-18: disclosed
  • 2024: patched: Fixed in QcalAgent 1.1.9 and later

References