QNAP’s Q’center Virtual Appliance web console includes a functionality that would allow an authenticated attacker to elevate privileges on the system. The application contains an API endpoint that returns information about the accounts defined in the database. The information returned is informative for all the users except for the admin user, where an extra field (new_password) contains the password defined at installation time for the. admin user. Any authenticated user could access this API endpoint and retrieve the admin. user’s password, therefore being able to login as an administrator.”]

