Vulnerability Description
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Qes | < 2.1.1 |
Related Weaknesses (CWE)
References
- https://www.qnap.com/zh-tw/security-advisory/qsa-20-17Vendor Advisory
- https://www.qnap.com/zh-tw/security-advisory/qsa-20-17Vendor Advisory
FAQ
What is CVE-2020-2503?
CVE-2020-2503 is a vulnerability with a CVSS score of 9.0 (CRITICAL). If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and ...
How severe is CVE-2020-2503?
CVE-2020-2503 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-2503?
Check the references section above for vendor advisories and patch information. Affected products include: Qnap Qes.