A path traversal vulnerability has been reported to affect Qfiling. The remote attackers can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following version:
Qfiling 3.13.1 and later
A path traversal vulnerability (CWE-22) in QNAP Qfiling versions prior to 3.13.1 allows remote attackers to read arbitrary files and system data without authentication. The vulnerability carries a CVSS score of 7.5 (High) and affects file management operations. Organizations using QNAP Qfiling for document management must upgrade immediately to version 3.13.1 or later.
في طابور التحليل الذكي
سيتم تحليل هذا CVE تلقائياً في المهام المجدولة.