CVE-2019-7184

MEDIUM

QNAP Video Station < 5.4.3 - Stored Cross-Site Scripting

Title source: llm
STIX 2.1

Description

This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Video Station to their latest versions.

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
qnap/video_station < 5.4.3
Published Dec 05, 2019
Tracked Since Feb 18, 2026