This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later
References
Link | Resource |
---|---|
https://www.qnap.com/en/security-advisory/qsa-21-06 | Vendor Advisory |
Configurations
Information
Published : 2021-02-16 20:15
Updated : 2021-02-22 11:14
NVD link : CVE-2020-2502
Mitre link : CVE-2020-2502
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
qnap
- photo_station