A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
QuMagie 2.8.1 and later
References
| Link | Resource |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-25-49 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-01-02 15:16
Updated : 2026-01-05 20:30
NVD link : CVE-2025-62857
Mitre link : CVE-2025-62857
CVE.ORG link : CVE-2025-62857
JSON object : View
Products Affected
qnap
- qumagie
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
