Lucene search

K
cvelistQnapCVELIST:CVE-2019-7185
HistoryDec 05, 2019 - 4:48 p.m.

CVE-2019-7185

2019-12-0516:48:20
qnap
www.cve.org
1

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.2%

This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.

CNA Affected

[
  {
    "product": "QNAP NAS devices running Music Station",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "QTS 4.4.1: Music Station before version 5.3.5, QTS 4.3.6 - QTS 4.4.0: Music Station before version 5.2.7, QTS 4.3.0 - QTS 4.3.4: Music Station before version 5.1.11"
      }
    ]
  }
]

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.2%

Related for CVELIST:CVE-2019-7185