CVE-2021-38681
Summary
| CVE | CVE-2021-38681 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-11-20 01:15:00 UTC |
| Updated | 2021-11-23 13:50:00 UTC |
| Description | A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qnap | Nas | - | All | All | All |
| Application | Qnap | Ragic Cloud Db | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Reflected XSS Vulnerability in Ragic Cloud DB - Security Advisory | QNAP | CONFIRM | www.qnap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.