← Back to browse · API

CVE-2023-34976

Severity
CRITICAL
CVSS
10.0
EPSS
0.00509
Risk score
40.18
CISA KEV
No
PoC
No
Published
2023-10-13
Modified
2026-01-12
First seen
2026-08-07
Aliases
EUVD-2023-39015, GHSA-P9MF-X9HH-R538
Products
QNAP Systems Inc.:Video Station 5.7.x <5.7.0 ( 2023/07/27 )
Sources
euvd EUVD-2023-39015

Description

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Video Station 5.7.0 ( 2023/07/27 ) and later

References