PT-2019-6063 · Qnap · Qnap Photo Station
Henry Huang
·
Published
2019-12-05
·
Updated
2025-02-13
·
CVE-2019-7195
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QNAP Photo Station (affected versions not specified)
Description
The issue allows remote attackers to access or modify system files due to an external control of file name or path vulnerability. This vulnerability is related to incorrect limitation of the directory path name with limited access. Exploitation of the vulnerability may allow a remote attacker to compromise data integrity.
Recommendations
To fix the vulnerability, update Photo Station to the latest version.
As a temporary workaround, consider restricting access to sensitive system files until a patch is available.
Avoid using the vulnerable Photo Station application until the issue is resolved.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnap Photo Station