First published: Fri Oct 01 2021(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <5.4.10 | |
QNAP Photo Station | >=5.7.0<5.7.13 | |
QNAP Photo Station | >=6.0.0<6.0.18 | |
QNAP NAS |
We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34355 is a cross-site scripting (XSS) vulnerability reported in QNAP NAS running Photo Station.
If exploited, CVE-2021-34355 allows remote attackers to inject malicious code into QNAP NAS running Photo Station.
The affected versions of Photo Station are 5.4.10, 5.7.0 to 5.7.13, and 6.0.0 to 6.0.18.
Yes, the vulnerability has been fixed in Photo Station version 5.4.10.
You can find more information about CVE-2021-34355 in the QNAP security advisory QSA-21-42 at https://www.qnap.com/en/security-advisory/qsa-21-42.