CSRF Bypass in Proxy Server
CVE-2021-34360

5.3MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
26 May 2022

Summary

A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Proxy Server: QTS 4.5.x: Proxy Server 1.4.2 ( 2021/12/30 ) and later QuTS hero h5.0.0: Proxy Server 1.4.3 ( 2022/01/18 ) and later QuTScloud c4.5.6: Proxy Server 1.4.2 ( 2021/12/30 ) and later

Affected Version(s)

Proxy Server QTS 4.5.x < 1.4.2 ( 2021/12/30 )

Proxy Server QuTS hero h5.0.0 < 1.4.3 ( 2022/01/18 )

Proxy Server QuTScloud c4.5.6 < 1.4.2 ( 2021/12/30 )

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tony Martin, a security researcher
.