Cross-Site Scripting Vulnerability in QuLog Center by QNAP
CVE-2025-54168
2.2LOW
What is CVE-2025-54168?
A cross-site scripting (XSS) vulnerability exists in QuLog Center that may allow an attacker, with administrative access, to circumvent security protocols or access sensitive application data. This vulnerability is critical to address as it exposes users to potential data breaches and unauthorized control over the application. The issue has been resolved in versions 1.8.2.923 and later, emphasizing the importance of staying updated to mitigate such risks.
Affected Version(s)
QuLog Center 1.8.x.x < 1.8.2.923 ( 2025/08/27 )
References
CVSS V4
Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mohammad Abdullah - Infosec Researcher & Bugbounty hunter