CVE-2017-13073: XSS
Published Apr 23, 2018
·Updated
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
Affected Software
2 affected components
QNAP Photo Station>=5.2.0<=5.2.7
QNAP Photo Station>=5.4.0<=5.4.3
Event History
Apr 23, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-13073?
The severity of CVE-2017-13073 is medium with a CVSS score of 6.1.
2
How does CVE-2017-13073 affect QNAP NAS application Photo Station?
CVE-2017-13073 is a cross-site scripting (XSS) vulnerability that affects QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions.
3
What can remote attackers do with CVE-2017-13073?
Remote attackers can inject arbitrary web script or HTML through CVE-2017-13073.
4
How can I fix CVE-2017-13073 in QNAP NAS application Photo Station?
To fix CVE-2017-13073, you should update QNAP NAS application Photo Station to version 5.4.4 or above.
5
Where can I find more information about CVE-2017-13073?
You can find more information about CVE-2017-13073 in the QNAP security advisory at https://www.qnap.com/zh-tw/security-advisory/nas-201804-23.