Vulnerability Details CVE-2019-7185
This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.6%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2019-7185
-
cpe:2.3:a:qnap:music_station:-
-
cpe:2.3:a:qnap:music_station:4.8.0
-
cpe:2.3:a:qnap:music_station:4.8.1
-
cpe:2.3:a:qnap:music_station:4.8.11
-
cpe:2.3:a:qnap:music_station:4.8.2
-
cpe:2.3:a:qnap:music_station:4.8.4
-
cpe:2.3:a:qnap:music_station:4.8.6
-
cpe:2.3:a:qnap:music_station:4.8.7
-
cpe:2.3:a:qnap:music_station:4.8.8
-
cpe:2.3:a:qnap:music_station:5.0.0
-
cpe:2.3:a:qnap:music_station:5.0.1
-
cpe:2.3:a:qnap:music_station:5.0.2
-
cpe:2.3:a:qnap:music_station:5.0.3
-
cpe:2.3:a:qnap:music_station:5.0.4
-
cpe:2.3:a:qnap:music_station:5.0.5
-
cpe:2.3:a:qnap:music_station:5.0.6
-
cpe:2.3:a:qnap:music_station:5.0.7
-
cpe:2.3:a:qnap:music_station:5.0.8
-
cpe:2.3:a:qnap:music_station:5.0.9
-
cpe:2.3:a:qnap:music_station:5.1.0
-
cpe:2.3:a:qnap:music_station:5.1.1
-
cpe:2.3:a:qnap:music_station:5.1.10
-
cpe:2.3:a:qnap:music_station:5.1.11
-
cpe:2.3:a:qnap:music_station:5.1.12
-
cpe:2.3:a:qnap:music_station:5.1.13
-
cpe:2.3:a:qnap:music_station:5.1.14
-
cpe:2.3:a:qnap:music_station:5.1.16
-
cpe:2.3:a:qnap:music_station:5.1.2
-
cpe:2.3:a:qnap:music_station:5.1.3
-
cpe:2.3:a:qnap:music_station:5.1.4
-
cpe:2.3:a:qnap:music_station:5.1.5
-
cpe:2.3:a:qnap:music_station:5.1.6
-
cpe:2.3:a:qnap:music_station:5.1.7
-
cpe:2.3:a:qnap:music_station:5.1.8
-
cpe:2.3:a:qnap:music_station:5.1.9
-
cpe:2.3:a:qnap:music_station:5.2.0
-
cpe:2.3:a:qnap:music_station:5.2.1
-
cpe:2.3:a:qnap:music_station:5.2.10
-
cpe:2.3:a:qnap:music_station:5.2.2
-
cpe:2.3:a:qnap:music_station:5.2.3
-
cpe:2.3:a:qnap:music_station:5.2.4
-
cpe:2.3:a:qnap:music_station:5.2.5
-
cpe:2.3:a:qnap:music_station:5.2.6
-
cpe:2.3:a:qnap:music_station:5.2.7
-
cpe:2.3:a:qnap:music_station:5.2.8
-
cpe:2.3:a:qnap:music_station:5.2.9
-
cpe:2.3:a:qnap:music_station:5.3.0
-
cpe:2.3:a:qnap:music_station:5.3.1
-
cpe:2.3:a:qnap:music_station:5.3.2
-
cpe:2.3:a:qnap:music_station:5.3.3
-
cpe:2.3:a:qnap:music_station:5.3.4
-
cpe:2.3:o:qnap:qts:4.3.1.0013
-
cpe:2.3:o:qnap:qts:4.3.1.0023
-
cpe:2.3:o:qnap:qts:4.3.2.0050
-
cpe:2.3:o:qnap:qts:4.3.2.0060
-
cpe:2.3:o:qnap:qts:4.3.2.0144
-
-
cpe:2.3:o:qnap:qts:4.3.3.0095
-
cpe:2.3:o:qnap:qts:4.3.3.0096
-
cpe:2.3:o:qnap:qts:4.3.3.0136
-
cpe:2.3:o:qnap:qts:4.3.3.0154
-
cpe:2.3:o:qnap:qts:4.3.3.0174
-
cpe:2.3:o:qnap:qts:4.3.3.0188
-
cpe:2.3:o:qnap:qts:4.3.3.0210
-
cpe:2.3:o:qnap:qts:4.3.3.0229
-
cpe:2.3:o:qnap:qts:4.3.3.0238
-
cpe:2.3:o:qnap:qts:4.3.3.0262
-
cpe:2.3:o:qnap:qts:4.3.3.0299
-
cpe:2.3:o:qnap:qts:4.3.3.0351
-
cpe:2.3:o:qnap:qts:4.3.3.0353
-
cpe:2.3:o:qnap:qts:4.3.3.0361
-
cpe:2.3:o:qnap:qts:4.3.3.0369
-
cpe:2.3:o:qnap:qts:4.3.3.0378
-
cpe:2.3:o:qnap:qts:4.3.3.0396
-
cpe:2.3:o:qnap:qts:4.3.3.0404
-
cpe:2.3:o:qnap:qts:4.3.3.0416
-
cpe:2.3:o:qnap:qts:4.3.3.0418
-
cpe:2.3:o:qnap:qts:4.3.3.0448
-
cpe:2.3:o:qnap:qts:4.3.3.0514
-
cpe:2.3:o:qnap:qts:4.3.3.0546
-
cpe:2.3:o:qnap:qts:4.3.3.0570
-
cpe:2.3:o:qnap:qts:4.3.3.0868
-
cpe:2.3:o:qnap:qts:4.3.3.0998
-
cpe:2.3:o:qnap:qts:4.3.3.1051
-
cpe:2.3:o:qnap:qts:4.3.3.1098
-
cpe:2.3:o:qnap:qts:4.3.3.1161
-
cpe:2.3:o:qnap:qts:4.3.3.1252
-
cpe:2.3:o:qnap:qts:4.3.3.1315
-
cpe:2.3:o:qnap:qts:4.3.3.1386
-
cpe:2.3:o:qnap:qts:4.3.3.1432
-
cpe:2.3:o:qnap:qts:4.3.3.1624
-
cpe:2.3:o:qnap:qts:4.3.3.1677
-
cpe:2.3:o:qnap:qts:4.3.3.1693
-
cpe:2.3:o:qnap:qts:4.3.3.1799
-
cpe:2.3:o:qnap:qts:4.3.3.1864
-
cpe:2.3:o:qnap:qts:4.3.3.1945
-
cpe:2.3:o:qnap:qts:4.3.3.2057
-
cpe:2.3:o:qnap:qts:4.3.3.2211
-
cpe:2.3:o:qnap:qts:4.3.3.2420
-
cpe:2.3:o:qnap:qts:4.3.3.2644
-
cpe:2.3:o:qnap:qts:4.3.3.2784
-
cpe:2.3:o:qnap:qts:4.3.3.4132
-
-
-
cpe:2.3:o:qnap:qts:4.3.6.0895
-
cpe:2.3:o:qnap:qts:4.3.6.0907
-
cpe:2.3:o:qnap:qts:4.3.6.0923
-
cpe:2.3:o:qnap:qts:4.3.6.0944
-
cpe:2.3:o:qnap:qts:4.3.6.0959
-
cpe:2.3:o:qnap:qts:4.3.6.0979
-
cpe:2.3:o:qnap:qts:4.3.6.0993
-
cpe:2.3:o:qnap:qts:4.3.6.1013
-
cpe:2.3:o:qnap:qts:4.3.6.1033
-
cpe:2.3:o:qnap:qts:4.3.6.1070
-
cpe:2.3:o:qnap:qts:4.3.6.1154
-
cpe:2.3:o:qnap:qts:4.3.6.1218
-
cpe:2.3:o:qnap:qts:4.3.6.1263
-
cpe:2.3:o:qnap:qts:4.3.6.1286
-
cpe:2.3:o:qnap:qts:4.3.6.1333
-
cpe:2.3:o:qnap:qts:4.3.6.1411
-
cpe:2.3:o:qnap:qts:4.3.6.1446
-
cpe:2.3:o:qnap:qts:4.3.6.1620
-
cpe:2.3:o:qnap:qts:4.3.6.1663
-
cpe:2.3:o:qnap:qts:4.3.6.1711
-
cpe:2.3:o:qnap:qts:4.3.6.1750
-
cpe:2.3:o:qnap:qts:4.3.6.1831
-
cpe:2.3:o:qnap:qts:4.3.6.1907
-
cpe:2.3:o:qnap:qts:4.3.6.1965
-
cpe:2.3:o:qnap:qts:4.3.6.2050
-
cpe:2.3:o:qnap:qts:4.3.6.2232
-
cpe:2.3:o:qnap:qts:4.3.6.2441
-
cpe:2.3:o:qnap:qts:4.3.6.2665
-
cpe:2.3:o:qnap:qts:4.3.6.2805
-
-