ASUSTOR ADM
cpe:2.3:a:asustor:adm:*:*:*:*:*:*:*, +1 more
- >= 4.1.0, <= 4.3.3.RH61
- <= 5.0.0.RIN1
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the File Explorer and Text Editor components of ASUSTOR's ADM operating system. This vulnerability allows attackers to inject malicious scripts into these applications. The injected scripts could potentially access cookies or other sensitive information stored by the browser and used with the affected applications. The vulnerability affects ASUSTOR ADM versions 4.1.0 prior to 4.3.3.RH61, as well as ADM 5.0.0.RIN1 and earlier. Additionally, Text Editor versions 1.0.0.r112 and earlier are vulnerable.
Exploitation of this vulnerability allows for stored Cross-Site Scripting, where injected scripts are executed in the context of the user.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.