SSD Advisory – QNAP HelpDesk SQL Injection
Credit to Author: SSD / Maor Schwartz| Date: Mon, 09 Oct 2017 14:26:28 +0000
Vulnerability Summary The following advisory describes a SQL injection found in QTS Helpdesk versions 1.1.12 and earlier. QNAP helpdesk: “Starting from QTS 4.2.2 you can use the built-in Helpdesk app to directly submit help requests to QNAP from your NAS. To do so, ensure your NAS can reach the Internet, open Helpdesk from the App … Continue reading SSD Advisory – QNAP HelpDesk SQL Injection
Read more