SQL Injection Vulnerability in QNAP Operating System
CVE-2024-50387

Currently unrated

Key Information:

Vendor
QNAP
Vendor
CVE Published:
6 December 2024

Summary

A SQL injection vulnerability has been identified in multiple versions of the QNAP Operating System, allowing remote attackers to inject and execute malicious code. If left unpatched, this flaw poses a significant risk to data integrity and security within affected systems. QNAP has addressed this issue in the SMB Service version 4.15.002 and later, enhancing protection against such attacks.

References

Timeline

  • Vulnerability published

.