CVE-2018-19943 is a cross-site scripting (XSS) vulnerability affecting QNAP QTS operating systems, allowing remote attackers to inject malicious code. With a CVSS score of 5.4 (Medium), it requires user interaction and low privileges but can lead to limited confidentiality and integrity impacts. This vulnerability is actively exploited, notably by the eCh0raix ransomware campaign, despite a lack of public exploit code. QNAP has released patches for various QTS versions to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.2.6CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.1.0013, < 4.3.3.1252CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.4, < 4.3.4.1282CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.3.6, < 4.3.6.1263CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* | ||
>= 4.4.0, < 4.4.1.1261CPE matchmatch criteria | cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.