CVE-2023-41285: QuMagie
Published Nov 10, 2023
·Updated
A SQL injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following version: QuMagie 2.1.4 and later
Affected Software
1 affected component
QNAP Qumagie<2.1.4
Remediation
Information
We have already fixed the vulnerability in the following version:
QuMagie 2.1.4 and later
Event History
Nov 10, 2023
CVE Published
04:02 PM
Data Sourced
04:02 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-41285?
CVE-2023-41285 is a SQL injection vulnerability in QuMagie that allows authenticated users to inject malicious code via a network.
2
How does CVE-2023-41285 affect QuMagie?
CVE-2023-41285 affects QuMagie by allowing authenticated users to inject malicious code via a network.
3
What is the severity of CVE-2023-41285?
CVE-2023-41285 has a severity value of 8.8, which is considered high.
4
How can I fix CVE-2023-41285 in QuMagie?
To fix CVE-2023-41285 in QuMagie, update to version 2.1.4 or later.
5
Where can I find more information about CVE-2023-41285?
You can find more information about CVE-2023-41285 in the QNAP security advisory QSA-23-50.