CVE-2023-47561: Photo Station
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47561?
CVE-2023-47561 is a cross-site scripting (XSS) vulnerability that is rated as a medium severity issue.
How do I fix CVE-2023-47561?
To fix CVE-2023-47561, upgrade to Photo Station version 6.4.2 or later.
Who is affected by CVE-2023-47561?
Authenticated users of QNAP Photo Station versions 6.4.0 and earlier are affected by CVE-2023-47561.
What kind of attack is possible with CVE-2023-47561?
CVE-2023-47561 allows an attacker to inject malicious code through cross-site scripting to exploit the application.
When was CVE-2023-47561 reported?
CVE-2023-47561 was reported recently and has a fix available in the version released in 2023.