← Back to CVE List
CVE-2024-27123NVD
Description
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later
We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later
CVSS Base Metrics
CVSS v4 (4.0)
MEDIUM 5.2
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Weaknesses (CWE)
CWE-79 - CWE-79
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| QNAP Systems Inc. QcalAgent | 1.1.0 - < 1.1.9 | N/A |