CSRF Bypass in Proxy Server
CVE-2021-34360
5.3MEDIUM
Summary
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later
Affected Version(s)
Proxy Server QTS 4.5.x < 1.4.2 ( 2021/12/30 )
Proxy Server QuTS hero h5.0.0 < 1.4.3 ( 2022/01/18 )
Proxy Server QuTScloud c4.5.6 < 1.4.2 ( 2021/12/30 )
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tony Martin, a security researcher