CVE-2018-19956: XSS
Published Nov 2, 2020
·Updated
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Affected Software
2 affected components
QNAP Photo Station>=5.7.0<5.7.11
QNAP Photo Station>=6.0.0<6.0.10
Remediation
Information
QNAP have already fixed these issues in the following versions of Photo Station:
QTS 4.3.6: Photo Station 5.7.11 and later
QTS 4.4.3: Photo Station 6.0.10 and later
Event History
Nov 2, 2020
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-19956?
CVE-2018-19956 is a cross-site scripting vulnerability that affects earlier versions of Photo Station.
2
How does CVE-2018-19956 impact QNAP Photo Station?
If exploited, CVE-2018-19956 allows remote attackers to inject malicious code into QNAP Photo Station.
3
Which versions of Photo Station are affected by CVE-2018-19956?
CVE-2018-19956 affects QNAP Photo Station versions prior to 5.7.11 and versions prior to 6.0.10.
4
What is the severity of CVE-2018-19956?
CVE-2018-19956 has a severity rating of 6.1 (medium).
5
How can I fix CVE-2018-19956?
To fix CVE-2018-19956, update your QNAP Photo Station to version 5.7.11 or 6.0.10 or later.