QNAP QuFTP Service Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability exists in QuFTP Service versions 1.4.x, 1.5.x, and 1.6.x. This vulnerability allows remote attackers with administrator accounts to exploit the issue, potentially bypassing security mechanisms or accessing application data.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users are advised to update QuFTP Service to the latest version. Instructions for updating can be found in the QNAP App Center.
Added: Mar 20, 2026, 5:21 PM
Updated: Mar 20, 2026, 5:21 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.4exploitability
4.8remediation
0.0relevance
4.2threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
