CVE-2018-19955: XSS
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2018-19955?
CVE-2018-19955 is a cross-site scripting vulnerability in earlier versions of QNAP Photo Station that could allow remote attackers to inject malicious code.
Which versions of Photo Station are affected by CVE-2018-19955?
Photo Station versions prior to 5.7.11 and versions prior to 6.0.10 are affected by CVE-2018-19955.
How severe is CVE-2018-19955?
CVE-2018-19955 has a medium severity rating with a CVSS score of 6.1.
How can I fix CVE-2018-19955?
To fix CVE-2018-19955, update QNAP Photo Station to version 5.7.11 or newer for versions prior to 5.7.11, and to version 6.0.10 or newer for versions prior to 6.0.10.
Where can I find more information about CVE-2018-19955?
More information about CVE-2018-19955 can be found in the QNAP Security Advisory QSA-20-11: https://www.qnap.com/en/security-advisory/qsa-20-11