First published: Fri Sep 06 2024(Updated: )
A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 ) and later
Credit: security@qnapsecurity.com.tw
Affected Software | Affected Version | How to fix |
---|---|---|
QNAP Video Station | >=5.0.0<5.8.2 |
We have already fixed the vulnerability in the following version: Video Station 5.8.1 ( 2024/02/26 ) and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-50360 is a critical SQL injection vulnerability that could allow authenticated users to execute malicious code.
The vulnerability can be fixed by upgrading to Video Station version 5.8.1 or later, released on February 26, 2024.
CVE-2023-50360 affects users of QNAP Video Station versions between 5.0.0 and 5.8.2.
Exploitation of CVE-2023-50360 can enable attackers to perform SQL injection attacks, potentially giving them unauthorized access and control.
Yes, exploitation of CVE-2023-50360 requires authentication, meaning only authenticated users can perform the injection.