
====================================================================

                             CERT-Renater

                 Note d'Information No. 2021/VULN305
_____________________________________________________________________

DATE                : 03/06/2021

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running QNAP NAS running Q’center versions
                                prior to 1.12.1012, 1.10.1004.

=====================================================================
https://www.qnap.com/fr-fr/security-advisory/qsa-21-20
_____________________________________________________________________


 Post-Authentication Reflected XSS Vulnerability in Q'center

    Release date: June 3, 2021
    Security ID: QSA-21-20
    Severity: High
    CVE identifier: CVE-2021-28807
    Affected products: QNAP NAS running Q’center
    Status: Resolved


Summary

A post-authentication reflected XSS vulnerability has been reported to
affect QNAP NAS running Q’center. If exploited, this vulnerability
allows remote attackers to inject malicious code.

We have already fixed this vulnerability in the following versions of
Q’center:

    QTS 4.5.3: Q’center v1.12.1012 and later
    QTS 4.3.6: Q’center v1.10.1004 and later
    QTS 4.3.3: Q’center v1.10.1004 and later
    QuTS hero h4.5.2: Q’center v1.12.1012 and later
    QuTScloud c4.5.4: Q’center v1.12.1012 and later


Recommendation

To fix the vulnerability, we recommend updating Q’center to the latest
version.

Updating Q’center

    Log on to QTS or QuTS hero as administrator.
    Open the App Center and then click .
    A search box appears.
    Type “Q’center” and then press ENTER.
    Q’center appears in the search results.
    Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your version is already
       up to date.
    Click OK.
    The application is updated.


Acknowledgements: Andrea Cappa

Revision History: V1.0 (June 3, 2021) - Published

=========================================================
+ CERT-RENATER       |    tel : 01-53-94-20-44          +
+ 23/25 Rue Daviel   |    fax : 01-53-94-20-41          +
+ 75013 Paris        |    email:cert@support.renater.fr +
=========================================================



