CVE-2024-27122: Notes Station 3
Published Sep 6, 2024
·Updated
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
Affected Software
1 affected component
QNAP Notes Station 3>=3.9.0<3.9.6
Remediation
Information
We have already fixed the vulnerability in the following versions:
Notes Station 3 3.9.6 and later
Event History
Sep 6, 2024
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27122?
CVE-2024-27122 is classified as a cross-site scripting (XSS) vulnerability that can impact authenticated user sessions.
2
How do I fix CVE-2024-27122?
To fix CVE-2024-27122, upgrade to Notes Station 3 version 3.9.6 or later.
3
Who is affected by CVE-2024-27122?
CVE-2024-27122 affects authenticated users of Notes Station 3 versions prior to 3.9.6.
4
What type of vulnerability is CVE-2024-27122?
CVE-2024-27122 is a cross-site scripting (XSS) vulnerability.
5
What can attackers achieve by exploiting CVE-2024-27122?
Attackers can inject malicious code into authenticated user sessions via CVE-2024-27122.