CVE-2020-2502

MEDIUM

QNAP Photo Station < 6.0.11 - Cross-Site Scripting

Title source: llm
STIX 2.1

Description

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.qnap.com/en/security-advisory/qsa-21-06

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 46.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-80 CWE-79
Status published
Products (1)
qnap/photo_station < 6.0.11
Published Feb 17, 2021
Tracked Since Feb 18, 2026