CVE-2024-32770

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*

History

20 Sep 2025, 03:35

Type Values Removed Values Added
First Time Qnap
Qnap photo Station
References () https://www.qnap.com/en/security-advisory/qsa-24-39 - () https://www.qnap.com/en/security-advisory/qsa-24-39 - Vendor Advisory
Summary
  • (es) Se ha informado de una vulnerabilidad de cross-site scripting (XSS) que afecta a Photo Station. Si se explota, la vulnerabilidad podría permitir que atacantes remotos que hayan obtenido acceso de usuario inyecten código malicioso. Ya hemos corregido la vulnerabilidad en la siguiente versión: Photo Station 6.4.3 (12/07/2024) y posteriores
CPE cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:*

22 Nov 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-22 16:15

Updated : 2025-09-20 03:35


NVD link : CVE-2024-32770

Mitre link : CVE-2024-32770

CVE.ORG link : CVE-2024-32770


JSON object : View

Products Affected

qnap

  • photo_station
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')