Cross-Site Scripting Vulnerability in QcalAgent by QNAP
CVE-2024-27123
5.2MEDIUM
What is CVE-2024-27123?
A cross-site scripting (XSS) vulnerability has been identified in QcalAgent, allowing local attackers to exploit the flaw to potentially bypass security measures or gain unauthorized access to application data. This vulnerability impacts QcalAgent versions prior to 1.1.9, emphasizing the need for users to update to the latest version to safeguard their systems against potential exploitation. For more details, refer to the official security advisory provided by QNAP.
Affected Version(s)
QcalAgent 1.1.0 < 1.1.9