CVE-2018-19952: SQL Injection
If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-19952?
CVE-2018-19952 is an SQL injection vulnerability that could allow remote attackers to obtain application information.
Which software versions are affected by CVE-2018-19952?
The following versions of QNAP Systems Inc. Music Station are affected: versions prior to 5.1.13, versions prior to 5.2.9, and versions prior to 5.3.11.
What is the severity of CVE-2018-19952?
CVE-2018-19952 has a severity rating of 7.5 (high).
How can I fix CVE-2018-19952?
To fix CVE-2018-19952, it is recommended to update QNAP Systems Inc. Music Station to version 5.1.13 or higher, 5.2.9 or higher, or 5.3.11 or higher.
Where can I find more information about CVE-2018-19952?
You can find more information about CVE-2018-19952 on the QNAP Systems Inc. security advisory page: https://www.qnap.com/en/security-advisory/qsa-20-10