First published: Mon Apr 23 2018(Updated: )
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | >=5.2.0<=5.2.7 | |
QNAP Photo Station | >=5.4.0<=5.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-13073 is medium with a CVSS score of 6.1.
CVE-2017-13073 is a cross-site scripting (XSS) vulnerability that affects QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions.
Remote attackers can inject arbitrary web script or HTML through CVE-2017-13073.
To fix CVE-2017-13073, you should update QNAP NAS application Photo Station to version 5.4.4 or above.
You can find more information about CVE-2017-13073 in the QNAP security advisory at https://www.qnap.com/zh-tw/security-advisory/nas-201804-23.