VendorsAsustordata_masterall versions
Vulnerabilities

Asustor Data Master

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

45CVEs
CVE-2018-12305
Cross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with embedded JavaScript.
Published 2018-12-04 · Modified
6.1EPSS 0.007
CVE-2018-15699
ASUSTOR Data Master 3.1.5 and below makes an HTTP request for a configuration file that is vulnerable to XSS. A man in the middle can take advantage of this by inserting Javascript into the configuration files Version field.
Published 2018-08-27 · Modified
6.1EPSS 0.006
CVE-2018-12310
Cross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement feature.
Published 2018-12-04 · Modified
5.4EPSS 0.005
CVE-2018-12311
Cross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a file is moved via a malicious filename.
Published 2018-12-04 · Modified
5.4EPSS 0.005
CVE-2018-15696
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to enumerate all user accounts via user.cgi.
Published 2018-08-27 · Modified
4.3EPSS 0.007
← Prev2 / 2