Stored cross-site scripting vulnerability in QES
CVE-2020-2503
9CRITICAL
What is CVE-2020-2503?
If exploited, this stored cross-site scripting vulnerability could allow remote attackers to inject malicious code in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Affected Version(s)
QES build 20201006 < 2.1.1