Cross-site Scripting Vulnerability in Photo Station
CVE-2020-2491

6.1MEDIUM

Key Information:

Vendor
QNAP
Vendor
CVE Published:
7 December 2020

Summary

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later

Affected Version(s)

Photo Station < 6.0.12 < 6.0.12

Photo Station < 5.7.12 < 5.7.12

Photo Station < 5.7.13 < 5.7.13

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jan Hoff
.