CVE-2018-19943
QNAP NAS File Station Cross-Site Scripting Vulnerability
CVSS
8.0
High
EPSS
17.7%
p97
KEV
YES
May 24, 2022
Exploit Today
79
0-100
Published: Oct 28, 2020 · Last modified: Aug 13, 2026 · CWE-79 · CWE-80
Product
QNAP / Network Attached Storage (NAS)
Vulnerability
QNAP NAS File Station Cross-Site Scripting Vulnerability
Added to KEV
May 24, 2022
Remediate by
Jun 14, 2022
Known ransomware use
Yes
Summary description
A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2018-19943
If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later