Description
A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Notification Center 2.1.0.3443 and later Notification Center 1.9.2.3163 and later Notification Center 3.0.0.3466 and later
Problem types
Product status
2.1.x (custom) before 2.1.0.3443
1.9.x (custom) before 1.9.2.3163
3.0.x (custom) before 3.0.0.3466
Credits
Mohammad Abdullah - Infosec Researcher & Bugbounty hunter
References
www.qnap.com/en/security-advisory/qsa-25-40