---
id: CVE-2024-27123
title: >-
  A cross-site scripting (XSS) vulnerability has been reported to affect
  QcalAgent
summary: >-
  A cross-site scripting (XSS) vulnerability has been reported to affect
  QcalAgent. The local attackers can then exploit the vulnerability to bypass
  security mechanisms or read application data.


  We have already fixed the vulnerability in …
severity: medium
cvss: 5.2
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'
cwe:
  - CWE-79
vendor: QNAP Systems Inc.
product: QcalAgent
affected:
  - QcalAgent >= 1.1.0 < 1.1.9
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:29:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-27123'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-24-54'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
  - cve.org
epss: 0.00129
epssPercentile: 0.02122
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T14:15:17.149405Z'
cvssSource: cna
ingestedAt: '2026-09-18T07:37:23.429Z'
---

## Overview

A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data.

We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
