CVE-2024-27126: Notes Station 3
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27126?
CVE-2024-27126 is classified as a cross-site scripting (XSS) vulnerability with potential impact on user security.
How do I fix CVE-2024-27126?
To fix CVE-2024-27126, update your Qnap Notes Station 3 to version 3.9.6 or later.
Who is affected by CVE-2024-27126?
CVE-2024-27126 affects authenticated users of Qnap Notes Station 3 versions from 3.9.0 to 3.9.5.
What kind of attack can be executed due to CVE-2024-27126?
Exploitation of CVE-2024-27126 can allow attackers to inject malicious scripts via the application interface.
Is there a way to determine if my version is vulnerable to CVE-2024-27126?
You can determine vulnerability by checking if your Qnap Notes Station 3 is running a version between 3.9.0 and 3.9.5.