Vulnerability Details CVE-2024-12923
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version:
Photo Station 6.4.5 ( 2025/01/02 ) and later
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 34.8%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2024-12923
-
cpe:2.3:a:qnap:photo_station:6.4.0
-
cpe:2.3:a:qnap:photo_station:6.4.1
-
cpe:2.3:a:qnap:photo_station:6.4.2
-
cpe:2.3:a:qnap:photo_station:6.4.3
-
cpe:2.3:a:qnap:photo_station:6.4.4