First published: Fri Feb 02 2024(Updated: )
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Photo Station Firmware | >=6.4.0<6.4.2 |
We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47561 is a cross-site scripting (XSS) vulnerability that is rated as a medium severity issue.
To fix CVE-2023-47561, upgrade to Photo Station version 6.4.2 or later.
Authenticated users of QNAP Photo Station versions 6.4.0 and earlier are affected by CVE-2023-47561.
CVE-2023-47561 allows an attacker to inject malicious code through cross-site scripting to exploit the application.
CVE-2023-47561 was reported recently and has a fix available in the version released in 2023.