CVE-2019-7185: XSS
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7185?
CVE-2019-7185 is a cross-site scripting (XSS) vulnerability in Music Station that allows remote attackers to inject and execute scripts on the administrator's management console.
How can I exploit CVE-2019-7185?
To exploit CVE-2019-7185, you need to inject malicious scripts into Music Station through a specially crafted request.
What is the severity of CVE-2019-7185?
CVE-2019-7185 has a severity rating of medium, with a CVSS score of 4.8.
How do I fix CVE-2019-7185?
To fix CVE-2019-7185, it is recommended to update Music Station to the latest version provided by QNAP.
Where can I find more information about CVE-2019-7185?
For more information about CVE-2019-7185, you can visit the QNAP security advisory page at [https://www.qnap.com/zh-tw/security-advisory/nas-201911-27](https://www.qnap.com/zh-tw/security-advisory/nas-201911-27).