First published: Thu Dec 10 2020(Updated: )
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station Firmware | <6.0.12 | |
QNAP QTS | =4.5.1 | |
QNAP QTS | =4.4.3 | |
QNAP Photo Station Firmware | <5.7.12 | |
QNAP QTS | =4.3.6 | |
QNAP Photo Station Firmware | <5.7.13 | |
QNAP QTS | =4.3.4 | |
QNAP Photo Station Firmware | <5.4.10 | |
QNAP QTS | =4.3.3 | |
QNAP Photo Station Firmware | <5.2.11 | |
QNAP QTS | =4.2.6 |
QNAP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13 and later QTS 4.3.3: Photo Station 5.4.10 and later QTS 4.2.6: Photo Station 5.2.11 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2491 is classified as a cross-site scripting vulnerability which can allow remote attackers to execute malicious code.
To fix CVE-2020-2491, upgrade to Photo Station 6.0.12 or later on QTS versions 4.5.1 and 4.4.3.
Photo Station versions prior to 6.0.12 are affected by CVE-2020-2491.
Yes, CVE-2020-2491 can be exploited by remote attackers without needing physical access to the system.
CVE-2020-2491 impacts QNAP Photo Station software running on certain QTS versions.