CVE-2021-34355
Stored XSS Vulnerability in Photo Station
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 ) and later Photo Station 6.0.18 ( 2021/09/01 ) and later
Se ha reportado de una vulnerabilidad de tipo cross-site scripting (XSS) que afecta al NAS de QNAP que ejecuta Photo Station. Si es explotado, esta vulnerabilidad permiten a atacantes remotos inyectar código malicioso. Ya hemos corregido esta vulnerabilidad en las siguientes versiones de Photo Station: Photo Station 5.4.10 (19/08/2021) y posteriores, Photo Station 5.7.13 (19/08/2021) y posteriores, Photo Station 6.0.18 (01/09/2021) y posteriores
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-08 CVE Reserved
- 2021-10-01 CVE Published
- 2023-04-23 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qnap.com/en/security-advisory/qsa-21-42 | 2021-10-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qnap Search vendor "Qnap" | Photo Station Search vendor "Qnap" for product "Photo Station" | < 5.4.10 Search vendor "Qnap" for product "Photo Station" and version " < 5.4.10" | - |
Affected
| in | Qnap Search vendor "Qnap" | Nas Search vendor "Qnap" for product "Nas" | - | - |
Safe
|
Qnap Search vendor "Qnap" | Photo Station Search vendor "Qnap" for product "Photo Station" | >= 5.7.0 < 5.7.13 Search vendor "Qnap" for product "Photo Station" and version " >= 5.7.0 < 5.7.13" | - |
Affected
| in | Qnap Search vendor "Qnap" | Nas Search vendor "Qnap" for product "Nas" | - | - |
Safe
|
Qnap Search vendor "Qnap" | Photo Station Search vendor "Qnap" for product "Photo Station" | >= 6.0.0 < 6.0.18 Search vendor "Qnap" for product "Photo Station" and version " >= 6.0.0 < 6.0.18" | - |
Affected
| in | Qnap Search vendor "Qnap" | Nas Search vendor "Qnap" for product "Nas" | - | - |
Safe
|