First published: Mon Dec 07 2020(Updated: )
This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Music Station | <5.3.13 | |
QNAP QuTS hero | =h4.5.1 | |
Qnap Music Station | <5.3.12 | |
QNAP QTS | =4.5.1 | |
QNAP QTS | =4.4.3 | |
QNAP QTS | =4.5.1 |
QNAP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-2494 is a cross-site scripting vulnerability in Music Station that allows remote attackers to inject malicious code.
Versions of Music Station up to 5.3.13 are affected by CVE-2020-2494.
Yes, QANP has fixed CVE-2020-2494 in the following versions of Music Station: QuTS hero h4.5.1 - Music Station 5.3.13 and later, QTS 4.5.1 - Music Station 5.3.12 and later, QTS 4.4.3 - Music Station 5.3.13 and later.
CVE-2020-2494 has a severity rating of 6.1 (Medium).
You can find more information about CVE-2020-2494 at the following link: [https://www.qnap.com/en/security-advisory/qsa-20-13](https://www.qnap.com/en/security-advisory/qsa-20-13)