- Description
- This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.
- Source
- security@qnapsecurity.com.tw
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 4.8
- Impact score
- 2.7
- Exploitability score
- 1.7
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 3.5
- Impact score
- 2.9
- Exploitability score
- 6.8
- Vector string
- AV:N/AC:M/Au:S/C:N/I:P/A:N
- nvd@nist.gov
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7773147-4835-4F95-A72A-E4758F457671",
"versionEndExcluding": "5.4.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:4.4.1:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "47B6D38A-D7C9-4D55-921C-488D56C43F25"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:video_station:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10F9A133-6D50-4EE9-80CE-7EE9555892FA",
"versionEndExcluding": "5.3.10"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:qnap:qts:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AD20D15E-C474-48FC-9A84-12CD6AF01F1F",
"versionEndIncluding": "4.4.0",
"versionStartIncluding": "4.3.4"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
]