Medium severity6.1CISA KEVNVD Advisory· Published Oct 28, 2020· Updated Aug 13, 2026
CVE-2018-19953
CVE-2018-19953
Description
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: <4.2.6
- cpe:2.3:o:qnap:qts:4.2.6:-:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.2.6:build_20170517:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.2.6:build_20190322:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.2.6:build_20190730:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.2.6:build_20190921:*:*:*:*:*:*
- cpe:2.3:o:qnap:qts:4.2.6:build_20191107:*:*:*:*:*:*
- (no CPE)range: up to 4.4.2.1231, up to 4.4.1.1201, up to 4.3.6.1218, up to 4.3.4.1190, up to 4.3.3.1161, up to 4.2.6
- QNAP Systems Inc./QTSv5Range: unspecified
Patches
Vulnerability mechanics
References
2- www.qnap.com/zh-tw/security-advisory/qsa-20-01nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.