CVE-2023-39299

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
03/11/2023
Last modified:
14/11/2023

Description

A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to read the contents of unexpected files and expose sensitive data via a network.<br /> <br /> We have already fixed the vulnerability in the following versions:<br /> Music Station 4.8.11 and later<br /> Music Station 5.1.16 and later<br /> Music Station 5.3.23 and later<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:* 4.8.0 (including) 4.8.11 (excluding)
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:* 5.1.0 (including) 5.1.16 (excluding)
cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.23 (excluding)


References to Advisories, Solutions, and Tools