Cross-Site Scripting Vulnerability in QcalAgent by QNAP
CVE-2024-27123

5.2MEDIUM

Key Information:

Vendor

QNAP

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2024-27123?

A cross-site scripting (XSS) vulnerability has been identified in QcalAgent, allowing local attackers to exploit the flaw to potentially bypass security measures or gain unauthorized access to application data. This vulnerability impacts QcalAgent versions prior to 1.1.9, emphasizing the need for users to update to the latest version to safeguard their systems against potential exploitation. For more details, refer to the official security advisory provided by QNAP.

Affected Version(s)

QcalAgent 1.1.0 < 1.1.9

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Anonymous
.