CVE-2023-32969: QNAP QTS
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. We have already fixed the vulnerability in the following versions: QuTScloud c5.1.5.2651 and later QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later
Affected products
- QNAP QTS: from 5.1.0, before 5.1.4.2596 (fixed in 5.1.4.2596); version 5.1.4.2596 only
- QNAP Quts Hero: from h5.1.0, before h5.1.4.2596 (fixed in h5.1.4.2596); version h5.1.4.2596 only
- QNAP Qutscloud: from c5.0.0.1919, before c5.1.5.2651 (fixed in c5.1.5.2651)
Published 2024-03-08. Last modified 2026-06-17.