ASUSTOR ADM and Text Editor Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the File Explorer and Text Editor components of ASUSTOR's ADM operating system. This vulnerability allows attackers to inject malicious scripts into these applications. The injected scripts could potentially access cookies or other sensitive information stored by the browser and used with the affected applications. The vulnerability affects ASUSTOR ADM versions 4.1.0 prior to 4.3.3.RH61, as well as ADM 5.0.0.RIN1 and earlier. Additionally, Text Editor versions 1.0.0.r112 and earlier are vulnerable.

Impact

Exploitation of this vulnerability allows for stored Cross-Site Scripting, where injected scripts are executed in the context of the user.

Added: Jul 14, 2025, 11:16 AM
Updated: Jul 14, 2025, 11:16 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
1.3
exploitability
5.0
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.