First published: Mon Aug 27 2018(Updated: )
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <=5.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0715 is a cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier.
CVE-2018-0715 has a severity value of 6.1, which is considered medium.
CVE-2018-0715 allows remote attackers to inject Javascript code in the compromised application.
CVE-2018-0715 has a CWE ID of 79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2018-0715, you should update QNAP Photo Station to a version that is later than 5.7.0.