CVE-2023-41287: Video Station
Published Jan 5, 2024
·Updated
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network.
We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
Affected Software
1 affected component
QNAP Video Station>=5.7.0<5.7.2
Remediation
Information
We have already fixed the vulnerability in the following version:
Video Station 5.7.2 ( 2023/11/23 ) and later
Event History
Jan 5, 2024
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-41287?
The severity of CVE-2023-41287 is classified as high due to its ability to allow SQL injection attacks.
2
How do I fix CVE-2023-41287?
To fix CVE-2023-41287, upgrade to Video Station version 5.7.2 or later.
3
Which versions of Video Station are affected by CVE-2023-41287?
Versions of Video Station from 5.7.0 to 5.7.1 are affected by CVE-2023-41287.
4
Can CVE-2023-41287 be exploited remotely?
Yes, CVE-2023-41287 can be exploited remotely through the network.
5
What type of vulnerability is CVE-2023-41287?
CVE-2023-41287 is a SQL injection vulnerability.