KEVIntel
8.0
CVSS
High

CVE-2018-19943

PUBLISHED

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in...

Exploited in the wild Used in malware Remote
Vendor
QNAP Systems Inc.
Product
QTS
Published
Oct 28, 2020
EPSS

Description

If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. QNAP has already fixed these issues in the following QTS versions. QTS 4.4.2.1270 build 20200410 and later QTS 4.4.1.1261 build 20200330 and later QTS 4.3.6.1263 build 20200330 and later QTS 4.3.4.1282 build 20200408 and later QTS 4.3.3.1252 build 20200409 and later QTS 4.2.6 build 20200421 and later

windows cisa malware ransomware

CVSS scores

CVSS v3.1 8.0 High

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2022-05-24 00:00:00 UTC · Source

Used in malware

Recorded 2022-05-24 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA May 24, 2022

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel