RULE(RULE ID:330540)

Rule General Information
Release Date: 2020-07-06
Rule Name: TerraMaster NAS sysname Parameter Cross-Site Scripting Vulnerability (CVE-2018-13334)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting in handle.php in TerraMaster TOS version 3.1.03 allows attackers to execute JavaScript via the "options[sysname]" parameter.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Linux
Reference: https://blog.securityevaluators.com/vulnerabilities-in-terramaster-tos-3-1-03-fb99cf88b86a
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.terra-master.com/uk/tos/