CVE-2023-41284: QuMagie
Published Nov 10, 2023
·Updated
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later
Affected Software
1 affected component
QNAP Qumagie<2.1.4
Remediation
Information
We have already fixed the vulnerability in the following version:
QuMagie 2.1.4 and later
Event History
Nov 10, 2023
CVE Published
04:01 PM
Data Sourced
04:01 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-41284?
CVE-2023-41284 is a SQL injection vulnerability that affects QuMagie, a photo management software developed by Qnap.
2
How does CVE-2023-41284 impact QuMagie?
If exploited, CVE-2023-41284 allows authenticated users to inject malicious SQL code via a network.
3
What is the severity of CVE-2023-41284?
CVE-2023-41284 has a severity rating of 8.8 (high).
4
How can I fix CVE-2023-41284?
To fix CVE-2023-41284, you need to update QuMagie to version 2.1.4 or later.
5
Where can I find more information about CVE-2023-41284?
You can find more information about CVE-2023-41284 in the QNAP security advisory QSA-23-50.