First published: Fri Oct 13 2023(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later
Credit: security@qnapsecurity.com.tw security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Video Station | <2023.07.27 |
We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34977 is a cross-site scripting (XSS) vulnerability that affects Video Station, a software developed by Qnap.
The severity of CVE-2023-34977 is medium, with a CVSS score of 5.4.
CVE-2023-34977 allows authenticated users to inject malicious code into the Video Station network.
Video Station 5.7.0 (2023/07/27) and later versions have fixed the CVE-2023-34977 vulnerability.
You can find more information about CVE-2023-34977 in the Qnap security advisory QSA-23-52.