Qnap Photo Station vulnerabilities
25 known vulnerabilities affecting qnap/photo_station.
Total CVEs
25
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH2MEDIUM16LOW1
Vulnerabilities
Page 2 of 2
CVE-2019-7192CRITICALCVSS 9.8KEVPoCfixed in 6.0.3fixed in 5.7.10+2 more2019-12-05
CVE-2019-7192 [CRITICAL] CWE-863 CVE-2019-7192: This improper access control vulnerability allows remote attackers to gain unauthorized access to th
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
nvd
CVE-2019-7195CRITICALCVSS 9.8KEVPoCfixed in 6.0.3fixed in 5.7.10+2 more2019-12-05
CVE-2019-7195 [CRITICAL] CWE-22 CVE-2019-7195: This external control of file name or path vulnerability allows remote attackers to access or modify
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
nvd
CVE-2018-0722HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.2≥ 5.4.0, ≤ 5.4.4+2 more2019-02-01
CVE-2018-0722 [HIGH] CWE-22 CVE-2018-0722: Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and ea
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
cvelistv5nvd
CVE-2018-0715MEDIUMCVSS 6.1PoC≤ 5.7.0vversions 5.7.0 and earlier2018-08-27
CVE-2018-0715 [MEDIUM] CWE-79 CVE-2018-0715: Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remo
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
cvelistv5nvd
CVE-2017-13073MEDIUMCVSS 6.1≥ 5.2.0, ≤ 5.2.7≥ 5.4.0, ≤ 5.4.3+2 more2018-04-23
CVE-2017-13073 [MEDIUM] CWE-79 CVE-2017-13073: Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
cvelistv5nvd
← Previous2 / 2