This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
2019-12-05T17:15:12.887
2024-11-21T04:47:44.363
Modified
CVSSv3.1: 4.8 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | qnap | music_station | < 5.3.5 | Yes |
Operating System | qnap | qts | 4.4.1 | No |
Application | qnap | music_station | < 5.2.7 | Yes |
Operating System | qnap | qts | ≤ 4.4.0 | No |
Application | qnap | music_station | < 5.1.11 | Yes |
Operating System | qnap | qts | ≤ 4.3.4 | No |