First published: Mon Nov 02 2020(Updated: )
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | >=5.7.0<5.7.11 | |
QNAP Photo Station | >=6.0.0<6.0.10 |
QNAP have already fixed these issues in the following versions of Photo Station: QTS 4.3.6: Photo Station 5.7.11 and later QTS 4.4.3: Photo Station 6.0.10 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19955 is a cross-site scripting vulnerability in earlier versions of QNAP Photo Station that could allow remote attackers to inject malicious code.
Photo Station versions prior to 5.7.11 and versions prior to 6.0.10 are affected by CVE-2018-19955.
CVE-2018-19955 has a medium severity rating with a CVSS score of 6.1.
To fix CVE-2018-19955, update QNAP Photo Station to version 5.7.11 or newer for versions prior to 5.7.11, and to version 6.0.10 or newer for versions prior to 6.0.10.
More information about CVE-2018-19955 can be found in the QNAP Security Advisory QSA-20-11: https://www.qnap.com/en/security-advisory/qsa-20-11