First published: Fri Oct 01 2021(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <6.0.18 | |
QNAP NAS |
We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34354 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Photo Station.
CVE-2021-34354 allows remote attackers to inject malicious code into QNAP devices running Photo Station.
Photo Station versions up to and excluding 6.0.18 are affected by CVE-2021-34354.
CVE-2021-34354 has a severity rating of high.
To fix CVE-2021-34354, update your Photo Station to version 6.0.18 or above.