QNAP QTS
cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*
- < 5.2.9.3492 build 20260507
A cross-site scripting (XSS) vulnerability has been identified in several QNAP operating system versions. This vulnerability allows remote attackers to bypass security mechanisms or access application data. Affected QNAP operating systems include QTS versions prior to 5.2.9.3492 build 20260507, QuTS hero versions prior to h5.2.9.3499 build 20260514, QuTS hero h5.3.4.3500 build 20260520 and earlier, and QuTS hero h6.0.0.3500 build 20260520 and earlier.
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Users can upgrade to QTS 5.2.9.3492 build 20260507 or later, or QuTS hero h5.2.9.3499 build 20260514 or later, QuTS hero h5.3.4.3500 build 20260520 or later, or QuTS hero h6.0.0.3500 build 20260520 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.