Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c84w-pfmp-9cxg

Опубликовано: 09 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

EPSS

Процентиль: 100%
0.9296
Критический

9.1 Critical

CVSS3

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 10
nvd
больше 3 лет назад

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVSS3: 10
fstec
больше 3 лет назад

Уязвимость приложения для хранения фотографий Photo Station, связанная с ошибками управления привилегиями, позволяющая нарушителю повысить свои привилегии в системе и выполнить произвольный код

EPSS

Процентиль: 100%
0.9296
Критический

9.1 Critical

CVSS3

Дефекты

CWE-610