First published: Thu Dec 05 2019(Updated: )
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Music Station | <5.3.5 | |
QNAP QTS | =4.4.1 | |
Qnap Music Station | <5.2.7 | |
QNAP QTS | >=4.3.6<=4.4.0 | |
Qnap Music Station | <5.1.11 | |
QNAP QTS | >=4.3.0<=4.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7185 is a cross-site scripting (XSS) vulnerability in Music Station that allows remote attackers to inject and execute scripts on the administrator's management console.
To exploit CVE-2019-7185, you need to inject malicious scripts into Music Station through a specially crafted request.
CVE-2019-7185 has a severity rating of medium, with a CVSS score of 4.8.
To fix CVE-2019-7185, it is recommended to update Music Station to the latest version provided by QNAP.
For more information about CVE-2019-7185, you can visit the QNAP security advisory page at [https://www.qnap.com/zh-tw/security-advisory/nas-201911-27](https://www.qnap.com/zh-tw/security-advisory/nas-201911-27).