First published: Fri Nov 03 2023(Updated: )
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
Qnap Music Station | >=4.8.0<4.8.11 | |
Qnap Music Station | >=5.1.0<5.1.16 | |
Qnap Music Station | >=5.3.0<5.3.23 |
We have already fixed the vulnerability in the following versions: Music Station 4.8.11 and later Music Station 5.1.16 and later Music Station 5.3.23 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39299 is a path traversal vulnerability affecting Music Station.
If exploited, CVE-2023-39299 could allow users to read the contents of unexpected files and expose sensitive data via a network.
Music Station versions 4.8.0 to 4.8.11, 5.1.0 to 5.1.16, and 5.3.0 to 5.3.23 are affected by CVE-2023-39299.
CVE-2023-39299 has a severity rating of 7.5 (high).
To fix CVE-2023-39299, you should update Music Station to the latest version available, which is not affected by the vulnerability.