Qnap Photo Station vulnerabilities

25 known vulnerabilities affecting qnap/photo_station.

Total CVEs
25
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH2MEDIUM16LOW1

Vulnerabilities

Page 2 of 2
CVE-2019-7192CRITICALCVSS 9.8KEVPoCfixed in 6.0.3fixed in 5.7.10+2 more2019-12-05
CVE-2019-7192 [CRITICAL] CWE-863 CVE-2019-7192: This improper access control vulnerability allows remote attackers to gain unauthorized access to th This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
nvd
CVE-2019-7195CRITICALCVSS 9.8KEVPoCfixed in 6.0.3fixed in 5.7.10+2 more2019-12-05
CVE-2019-7195 [CRITICAL] CWE-22 CVE-2019-7195: This external control of file name or path vulnerability allows remote attackers to access or modify This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
nvd
CVE-2018-0722HIGHCVSS 7.5≥ 5.7.0, ≤ 5.7.2≥ 5.4.0, ≤ 5.4.4+2 more2019-02-01
CVE-2018-0722 [HIGH] CWE-22 CVE-2018-0722: Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and ea Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
cvelistv5nvd
CVE-2018-0715MEDIUMCVSS 6.1PoC≤ 5.7.0vversions 5.7.0 and earlier2018-08-27
CVE-2018-0715 [MEDIUM] CWE-79 CVE-2018-0715: Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remo Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
cvelistv5nvd
CVE-2017-13073MEDIUMCVSS 6.1≥ 5.2.0, ≤ 5.2.7≥ 5.4.0, ≤ 5.4.3+2 more2018-04-23
CVE-2017-13073 [MEDIUM] CWE-79 CVE-2017-13073: Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3 Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
cvelistv5nvd