7.1
/ 10
HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H
Description
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following versions:
License Center 1.8.51 and later
License Center 1.9.51 and later
We have already fixed the vulnerability in the following versions:
License Center 1.8.51 and later
License Center 1.9.51 and later
Basic Information
ID
CVE-2025-22483
Source
qnap
Published
Aug 29, 2025 at 17:04
Modified
Aug 29, 2025 at 17:14
Affected Product
Vendor
QNAP Systems Inc.
Product
License Center
Version
1.8.x
Affected Versions
QNAP Systems Inc. License Center 1.8.x
QNAP Systems Inc. License Center 1.9.x
QNAP Systems Inc. License Center 1.9.x