CVE-2021-34354: Stored Cross-site Scripting Vulnerability in Photo Station
Published Oct 1, 2021
·Updated
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Affected Software
2 affected components
QNAP Photo Station<6.0.18
QNAP NAS
Remediation
Information
We have already fixed this vulnerability in the following versions of Photo Station:
Photo Station 6.0.18 ( 2021/09/01 ) and later
Event History
Oct 1, 2021
CVE Published
via MITRE·02:50 AM
Data Sourced
via MITRE·02:50 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-34354?
CVE-2021-34354 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Photo Station.
2
How does CVE-2021-34354 affect QNAP devices?
CVE-2021-34354 allows remote attackers to inject malicious code into QNAP devices running Photo Station.
3
Which versions of Photo Station are affected by CVE-2021-34354?
Photo Station versions up to and excluding 6.0.18 are affected by CVE-2021-34354.
4
What is the severity of CVE-2021-34354?
CVE-2021-34354 has a severity rating of high.
5
How can I fix CVE-2021-34354?
To fix CVE-2021-34354, update your Photo Station to version 6.0.18 or above.