CVE-2024-50406: License Center
Published Jun 6, 2025
·Updated
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version: License Center 1.9.49 and later
Affected Software
2 affected components
License Center License Center<1.9.49
QNAP License Center>=1.9.36<1.9.49
Remediation
Information
We have already fixed the vulnerability in the following version:
License Center 1.9.49 and later
Event History
Jun 6, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 57899
Event
via NVD·01:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-50406?
CVE-2024-50406 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-50406?
To fix CVE-2024-50406, update your License Center software to version 1.9.49 or later.
3
What can attackers do by exploiting CVE-2024-50406?
Attackers exploiting CVE-2024-50406 can potentially bypass security mechanisms and read sensitive application data.
4
Which versions of License Center are affected by CVE-2024-50406?
CVE-2024-50406 affects License Center versions prior to 1.9.49.
5
Is a user login required to exploit CVE-2024-50406?
Yes, attackers need to gain user access to exploit CVE-2024-50406.