ZeroHour

CVE-2020-2503

CVSS 3.1
5.4 medium
EPSS
<1%p54
Published
()
Modified
Description

If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.

Vendors
qnap
Products
qes
Weakness
CWE-79, CWE-80, CWE-749
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.