CVE-2020-2503: QNAP Qes
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Affected products
- QNAP Qes: before 2.1.1 (fixed in 2.1.1); version 2.1.1 only
Published 2020-12-24. Last modified 2026-06-17.