VYPR
Medium severity4.8NVD Advisory· Published Dec 4, 2019· Updated Jun 17, 2026

CVE-2019-7197

CVE-2019-7197

Description

A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, this vulnerability may allow an attacker to inject and execute scripts on the administrator console. To fix this vulnerability, QNAP recommend updating QTS to the latest version.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Qnap/Qts6 versions
    cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:o:qnap:qts:4.2.6:*:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.3:*:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.4:*:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.3.6:*:*:*:*:*:*:*
    • cpe:2.3:o:qnap:qts:4.4.1:*:*:*:*:*:*:*
    • (no CPE)
  • QNAP/QTSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.