Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
| Software | From | Fixed in |
|---|---|---|
| qnap / photo_station | 5.4.0 | 5.4.3.x |
| qnap / photo_station | 5.2.0 | 5.2.7.x |