First published: Fri Jan 05 2024(Updated: )
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Video Station | >=5.7.0<5.7.2 |
We have already fixed the vulnerability in the following version: Video Station 5.7.2 ( 2023/11/23 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-41287 is classified as high due to its ability to allow SQL injection attacks.
To fix CVE-2023-41287, upgrade to Video Station version 5.7.2 or later.
Versions of Video Station from 5.7.0 to 5.7.1 are affected by CVE-2023-41287.
Yes, CVE-2023-41287 can be exploited remotely through the network.
CVE-2023-41287 is a SQL injection vulnerability.