CVE-2020-2494Cross-site Scripting in Systems INC Music Station

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 49.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 24

Description

This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDqnap/music_station< 5.3.13+1
CVEListV5qnap_systems_inc/music_station< 5.3.13+1

🔴Vulnerability Details

2
GHSA
GHSA-jx9p-jf7x-8rr2: This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code2022-05-24
CVEList
Cross-site Scripting Vulnerability in Music Station2020-12-10
CVE-2020-2494 — Cross-site Scripting | cvebase