First published: Fri Oct 01 2021(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station | <6.0.18 | |
QNAP NAS |
We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34356 is a cross-site scripting (XSS) vulnerability that affects QNAP devices running Photo Station.
The severity of CVE-2021-34356 is rated as high with a severity value of 5.4.
CVE-2021-34356 allows remote attackers to inject malicious code in QNAP devices running Photo Station.
Yes, the vulnerability has been fixed in Photo Station version 6.0.18 and above.
You can find more information about CVE-2021-34356 in the QNAP security advisory QSA-21-41 at the following link: [https://www.qnap.com/en/security-advisory/qsa-21-41](https://www.qnap.com/en/security-advisory/qsa-21-41)