CVE-2021-34356
Published on: 09/30/2021 12:00:00 AM UTC
Last Modified on: 10/04/2021 03:54:00 PM UTC
Certain versions of Nas from Qnap contain the following vulnerability:
A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
- CVE-2021-34356 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
QNAP Systems Inc. - Photo Station version < 6.0.18 ( 2021/09/01 )
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 3.5 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Stored XSS Vulnerabilities in Photo Station - Security Advisory | QNAP | www.qnap.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Qnap | Nas | - | All | All | All |
Application | Qnap | Photo Station | All | All | All | All |
- cpe:2.3:h:qnap:nas:-:*:*:*:*:*:*:*:
- cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*:
Discovery Credit
Tony Martin, a security researcher
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-34356 : A cross-site scripting #XSS vulnerability has been reported to affect QNAP device running Photo… twitter.com/i/web/status/1… | 2021-10-01 02:57:33 |
![]() |
Severity: High CVE-2021-34354 | CVE-2021-34356 Stored XSS Vulnerability in Photo Station - Security Advisory | QNAP qnap.com/en/security-ad… | 2021-10-01 14:56:40 |
![]() |
CVE-2021-34356 A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Sta… twitter.com/i/web/status/1… | 2021-10-02 07:09:52 |