← Back to browse · API

CVE-2018-19953

Severity
MEDIUM
CVSS
6.1
EPSS
0.23894
Risk score
57.76
CISA KEV
Yes
PoC
No
Published
2022-05-24
Modified
2022-05-24
First seen
2026-08-07
Aliases
EUVD-2018-11624, GHSA-8H8X-7J55-4JP9
Products
QNAP Systems Inc.:QTS unspecified <4.2.6, QNAP Systems Inc.:QTS unspecified <4.3.3.1161, QNAP Systems Inc.:QTS unspecified <4.3.4.1190, QNAP Systems Inc.:QTS unspecified <4.3.6.1218, QNAP Systems Inc.:QTS unspecified <4.4.1.1201, QNAP Systems Inc.:QTS unspecified <4.4.2.1231, QNAP:Network Attached Storage (NAS)
Sources
cisa.gov CVE-2018-19953
euvd EUVD-2018-11624

Description

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

References