VDB

CVE-2024-32768

CVE-2024-32768 PUBLISHED CVSS 6.300000190734863 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later

EPSS 0.37% · 27.8th percentile

Risk Scores

CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
EPSS Score
0.37%
27.8th percentile

Affected Products

VendorProductVersions
qnapphoto_station6.4.0, 6.4.0
QNAP Systems Inc.Photo Station6.4.x, 6.4.x

Timeline

  • Nov 22, 2024 CVE Published
  • Nov 23, 2024 EPSS Score
  • Dec 12, 2024 EPSS Score
  • Dec 29, 2024 EPSS Score
  • Jan 16, 2025 EPSS Score
  • Jan 25, 2025 Coalition ESS Score
  • Feb 3, 2025 EPSS Score
  • Feb 20, 2025 EPSS Score
  • Mar 10, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
  • Apr 15, 2025 EPSS Score
  • May 2, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›