Vulnerability Details CVE-2021-38681
A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exploited, this vulnerability allows remote attackers to inject malicious code. QNAP have already disabled and removed Ragic Cloud DB from the QNAP App Center, pending a security patch from Ragic.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 48.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2021-38681
-
cpe:2.3:a:qnap:ragic_cloud_db:2.4
-
cpe:2.3:a:qnap:ragic_cloud_db:2.4.4
-
cpe:2.3:a:qnap:ragic_cloud_db:2.4.6
-
cpe:2.3:a:qnap:ragic_cloud_db:2.6.3
-
cpe:2.3:a:qnap:ragic_cloud_db:2.7.1
-
cpe:2.3:a:qnap:ragic_cloud_db:2.8.0
-
cpe:2.3:a:qnap:ragic_cloud_db:2.9.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.0.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.1.1
-
cpe:2.3:a:qnap:ragic_cloud_db:3.2.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.3.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.4.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.5.1
-
cpe:2.3:a:qnap:ragic_cloud_db:3.6.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.7.0
-
cpe:2.3:a:qnap:ragic_cloud_db:3.7.0.1
-