CVE-2021-34356: Stored XSS Vulnerability in Photo Station
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-34356?
CVE-2021-34356 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Photo Station.
What is the severity of CVE-2021-34356?
The severity of CVE-2021-34356 is rated as high with a severity value of 5.4.
How does CVE-2021-34356 affect QNAP devices?
CVE-2021-34356 allows remote attackers to inject malicious code in QNAP devices running Photo Station.
Has CVE-2021-34356 been fixed?
Yes, the vulnerability has been fixed in Photo Station version 6.0.18 and above.
Where can I find more information about CVE-2021-34356?
You can find more information about CVE-2021-34356 in the QNAP security advisory QSA-21-41 at the following link: [https://www.qnap.com/en/security-advisory/qsa-21-41](https://www.qnap.com/en/security-advisory/qsa-21-41)