VYPR
Medium severity6.1CISA KEVNVD Advisory· Published Oct 28, 2020· Updated Aug 13, 2026

CVE-2018-19953

CVE-2018-19953

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • Qnap/Qts8 versions
    cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*range: <4.2.6
    • cpe:2.3:o:qnap:qts:4.2.6:-:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.2.6:build_20170517:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.2.6:build_20190322:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.2.6:build_20190730:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.2.6:build_20190921:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.2.6:build_20191107:*:*:*:*:*:*
    • (no CPE)range: up to 4.4.2.1231, up to 4.4.1.1201, up to 4.3.6.1218, up to 4.3.4.1190, up to 4.3.3.1161, up to 4.2.6
  • QNAP Systems Inc./QTSv5
    Range: unspecified

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.