Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
References
Link Resource
https://www.exploit-db.com/exploits/45348/ Exploit Third Party Advisory VDB Entry
https://www.qnap.com/zh-tw/security-advisory/nas-201808-23 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: qnap

Published: 2018-08-23T00:00:00

Updated: 2018-09-09T09:57:01

Reserved: 2017-11-28T00:00:00


Link: CVE-2018-0715

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-08-27T13:29:00.243

Modified: 2018-11-02T17:25:22.233


Link: CVE-2018-0715

JSON object: View

cve-icon Redhat Information

No data.

CWE