CVE-2024-48862
Severity CVSS v4.0:
HIGH
Type:
CWE-59
Link Following
Publication date:
22/11/2024
Last modified:
08/12/2025
Description
A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to unintended locations and read or overwrite the contents of unexpected files.<br />
<br />
We have already fixed the vulnerability in the following versions:<br />
QuLog Center 1.7.0.831 ( 2024/10/15 ) and later<br />
QuLog Center 1.8.0.888 ( 2024/10/15 ) and later
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:* | 1.7.0.800 (including) | 1.7.0.831 (excluding) |
| cpe:2.3:a:qnap:qulog_center:*:*:*:*:*:*:*:* | 1.8.0.872 (including) | 1.8.0.888 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



