CVE-2017-13073

MEDIUM

QNAP Photo Station < 5.2.7 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0025
EPSS Percentile 48.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
qnap/photo_station 5.2.0 - 5.2.7
Published Apr 23, 2018
Tracked Since Feb 18, 2026