2.2
/ 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:U
Description
A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QuMagie 2.8.1 and later
We have already fixed the vulnerability in the following version:
QuMagie 2.8.1 and later
Basic Information
ID
CVE-2025-62857
Source
qnap
Published
Jan 2, 2026 at 14:51
Affected Product
Vendor
QNAP Systems Inc.
Product
QuMagie
Version
2.x
Affected Versions
QNAP Systems Inc. QuMagie 2.x