CVE-2020-2491: Cross-site Scripting Vulnerability in Photo Station
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2020-2491?
CVE-2020-2491 is classified as a cross-site scripting vulnerability which can allow remote attackers to execute malicious code.
How do I fix CVE-2020-2491?
To fix CVE-2020-2491, upgrade to Photo Station 6.0.12 or later on QTS versions 4.5.1 and 4.4.3.
What versions of Photo Station are affected by CVE-2020-2491?
Photo Station versions prior to 6.0.12 are affected by CVE-2020-2491.
Can CVE-2020-2491 be exploited remotely?
Yes, CVE-2020-2491 can be exploited by remote attackers without needing physical access to the system.
What software does CVE-2020-2491 impact?
CVE-2020-2491 impacts QNAP Photo Station software running on certain QTS versions.