VulnerabilityModified
CVE-2020-2502
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code.
MEDIUM 6.1EPSS 0.83%
Does this matter?
Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.
Description
This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.83% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79, CWE-80
- Affected
- qnap/photo station
- Source
- security@qnapsecurity.com.tw
References
- https://www.qnap.com/en/security-advisory/qsa-21-06Vendor Advisory
- https://www.qnap.com/en/security-advisory/qsa-21-06Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.