CVE-2018-0715: XSS
Published Aug 27, 2018
·Updated
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
Affected Software
1 affected component
QNAP Photo Station<=5.7.0
Event History
Aug 27, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-0715?
CVE-2018-0715 is a cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier.
2
What is the severity of CVE-2018-0715?
CVE-2018-0715 has a severity value of 6.1, which is considered medium.
3
How does CVE-2018-0715 affect QNAP Photo Station?
CVE-2018-0715 allows remote attackers to inject Javascript code in the compromised application.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-0715?
CVE-2018-0715 has a CWE ID of 79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
How can I fix CVE-2018-0715?
To fix CVE-2018-0715, you should update QNAP Photo Station to a version that is later than 5.7.0.