First published: Mon Nov 02 2020(Updated: )
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | >=5.7.0<5.7.11 | |
QNAP Photo Station | >=6.0.0<6.0.10 |
QNAP have already fixed these issues in the following versions of Photo Station: QTS 4.3.6: Photo Station 5.7.11 and later QTS 4.4.3: Photo Station 6.0.10 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19954 is a cross-site scripting vulnerability that affects earlier versions of QNAP Systems Inc. Photo Station.
If exploited, CVE-2018-19954 allows remote attackers to inject malicious code into Photo Station.
CVE-2018-19954 affects Photo Station versions prior to 5.7.11 and versions prior to 6.0.10.
The severity of CVE-2018-19954 is medium, with a CVSS score of 6.1.
To fix CVE-2018-19954, update Photo Station to version 5.7.11 or 6.0.10.