CVE-2023-39295: QuMagie
Published Nov 10, 2023
·Updated
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to execute commands via a network.
We have already fixed the vulnerability in the following version: QuMagie 2.1.3 and later
Affected Software
1 affected component
QNAP Qumagie<2.1.4
Remediation
Information
We have already fixed the vulnerability in the following version:
QuMagie 2.1.3 and later
Event History
Nov 10, 2023
CVE Published
04:01 PM
Data Sourced
04:01 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this QuMagie vulnerability?
The vulnerability ID for this QuMagie vulnerability is CVE-2023-39295.
2
What is the severity of CVE-2023-39295?
The severity of CVE-2023-39295 is high with a CVSS score of 8.8.
3
How does CVE-2023-39295 affect QuMagie?
CVE-2023-39295 is an OS command injection vulnerability that affects QuMagie. It allows authenticated users to execute commands via a network.
4
What version of QuMagie has the vulnerability been fixed in?
The vulnerability has been fixed in QuMagie version 2.1.3 and later.
5
Where can I find more information about CVE-2023-39295?
You can find more information about CVE-2023-39295 in the QNAP Security Advisory QSA-23-50.