Unrated severityNVD Advisory· Published Jun 7, 2013· Updated Apr 29, 2026
CVE-2013-0144
CVE-2013-0144
Description
Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.
Affected products
2cpe:2.3:o:qnap:viostor_network_video_recorder:4.0.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:qnap:viostor_network_video_recorder:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:h:qnap:viostor_network_video_recorder:-:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.kb.cert.org/vuls/id/927644nvdUS Government Resource
News mentions
0No linked articles in our index yet.