Qnap Security Advisory QSA-21-47
Status resolved, concerning reflected XSS vulnerability in QmailAgent
This is a Press Release edited by StorageNewsletter.com on November 16, 2021 at 2:01 pmQnap Systems, Inc. has published a security advisory concerning reflected XSS vulnerability in QmailAgent.
-
Release date: November 12, 2021
-
Security ID: QSA-21-47
-
Severity: Medium
-
CVE identifier: CVE-2021-34357
-
Affected products: Qnap NAS running QmailAgent
-
Status: Resolved
Summary
A reflected cross-site scripting (XSS) vulnerability has been reported to affect Qnap NAS running QmailAgent. If exploited, this vulnerability allows remote attackers to inject malicious code.
The company have already fixed this vulnerability in the following versions of QmailAgent:
-
QmailAgent 3.0.2 (2021/08/25) and later
Recommendation
To fix the vulnerability, we recommend updating QmailAgent to the latest version.
Updating QmailAgent
-
Log on to QTS or QuTS hero as administrator.
-
Open the App Center and then click .
A search box appears. -
Type ‘QmailAgent’ and then press ENTER.
QmailAgent appears in the search results. -
Click Update.
A confirmation message appears.
Note: The Update button is not available if your QmailAgent is already up to date. -
Click OK.
The application is updated.
Acknowledgements: Tony Martin, a security researcher
Revision history: V1.0 (November 12, 2021) – Published