安全ID : NAS-201805-16
Security Advisory for XSS Vulnerability in App Center
发布日期 : May 16, 2018
通用漏洞披露 : CVE-2017-13072
受影响产品: App Center in QTS 4.2.6 build 20171208, QTS 4.3.3 build 20171213, QTS 4.3.4 build 20171223, and earlier versions
严重程度
Moderate
状态
已解决
Summary
A cross-site scripting vulnerability has been reported to affect App Center in QTS 4.2.6 build 20171208, 4.3.3 build 20171213, 4.3.4 build 20171223 and their earlier versions.
If successfully exploited, the vulnerability could allow remote attackers to inject Javascript code in the compromised application.
We have already fixed these issues in the following QTS versions.
- QTS 4.2.6 build 20180504 and later
- QTS 4.3.3 build 20180126 and later
- QTS 4.3.4 build 20171230 and later
Recommendation
To fix these vulnerabilities, you must update QTS to the following versions.
- QTS 4.2.6 build 20180504 or later
- QTS 4.3.3 build 20180126 or later
- QTS 4.3.4 build 20171230 or later
Installing the QTS Update
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
Tip: You can also download the update from the QNAP website. Go to Support > Download, and then perform a manual update.
致谢: Jesse Huang
修订历史: V1.0 (May 16, 2018) - Published