Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2020-36195

An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia Console and the Media Streaming add-on. QTS 4.3.3: Media Streaming add-on 430.1.8.10 and later QTS 4.3.6: Media Streaming add-on 430.1.8.8 and later QTS 4.4.x and later: Multimedia Console 1.3.4 and later We have also fixed this vulnerability in the following versions of QTS 4.3.3 and QTS 4.3.6, respectively: QTS 4.3.3.1624 Build 20210416 or later QTS 4.3.6.1620 Build 20210322 or later

  • Published: Apr 17, 2021
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-36195
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/Au:N/C:P/I:P/A:P

CWEs:

OWASP TOP 10:

Software From Fixed in
qnap / qts 4.3.3.0229 4.3.3.0229.x
qnap / qts 4.3.3 4.3.3.x
qnap / qts 4.3.3.0570 4.3.3.0570.x
qnap / qts 4.3.3.0546 4.3.3.0546.x
qnap / qts 4.3.3.0514 4.3.3.0514.x
qnap / qts 4.3.6.1033 4.3.6.1033.x
qnap / qts 4.3.6.1013 4.3.6.1013.x
qnap / qts 4.3.6.0993 4.3.6.0993.x
qnap / qts 4.3.6.0979 4.3.6.0979.x
qnap / qts 4.3.6.0959 4.3.6.0959.x
qnap / qts 4.3.6.0944 4.3.6.0944.x
qnap / qts 4.3.6.0923 4.3.6.0923.x
qnap / qts 4.3.6.0907 4.3.6.0907.x
qnap / qts 4.3.6.0895 4.3.6.0895.x
qnap / qts 4.3.3.0998 4.3.3.0998.x
qnap / qts 4.3.3.0868 4.3.3.0868.x
qnap / qts 4.3.3.1315 4.3.3.1315.x
qnap / qts 4.3.3.1386 4.3.3.1386.x
qnap / qts 4.3.3.0095 4.3.3.0095.x
qnap / qts 4.3.3.0096 4.3.3.0096.x
qnap / qts 4.3.3.0136 4.3.3.0136.x
qnap / qts 4.3.3.0154 4.3.3.0154.x
qnap / qts 4.3.3.0174 4.3.3.0174.x
qnap / qts 4.3.3.0188 4.3.3.0188.x
qnap / qts 4.3.3.0210 4.3.3.0210.x
qnap / qts 4.3.3.0238 4.3.3.0238.x
qnap / qts 4.3.3.0262 4.3.3.0262.x
qnap / qts 4.3.3.0299 4.3.3.0299.x
qnap / qts 4.3.3.0351 4.3.3.0351.x
qnap / qts 4.3.3.0353 4.3.3.0353.x
qnap / qts 4.3.3.0361 4.3.3.0361.x
qnap / qts 4.3.3.0369 4.3.3.0369.x
qnap / qts 4.3.3.0378 4.3.3.0378.x
qnap / qts 4.3.3.0396 4.3.3.0396.x
qnap / qts 4.3.3.0404 4.3.3.0404.x
qnap / qts 4.3.3.0416 4.3.3.0416.x
qnap / qts 4.3.3.0418 4.3.3.0418.x
qnap / qts 4.3.3.0448 4.3.3.0448.x
qnap / qts 4.3.3.1051 4.3.3.1051.x
qnap / qts 4.3.3.1098 4.3.3.1098.x
qnap / qts 4.3.3.1161 4.3.3.1161.x
qnap / qts 4.3.3.1252 4.3.3.1252.x
qnap / qts 4.3.6.1286 4.3.6.1286.x
qnap / qts 4.3.6.1333 4.3.6.1333.x
qnap / qts 4.3.6.1411 4.3.6.1411.x
qnap / qts 4.3.6 4.3.6.x
qnap / qts 4.3.6.1070 4.3.6.1070.x
qnap / qts 4.3.6.1154 4.3.6.1154.x
qnap / qts 4.3.6.1218 4.3.6.1218.x
qnap / qts 4.3.6.1263 4.3.6.1263.x
qnap / qts 4.3.6.1446 4.3.6.1446.x
qnap / qts 4.3.3.1432 4.3.3.1432.x
qnap / qts - 4.3.3
qnap / qts 4.3.4 4.3.6
qnap / media_streaming_add-on - 430.1.8.10
qnap / media_streaming_add-on - 430.1.8.8
qnap / multimedia_console - 1.3.4