← Back to browse · API

CVE-2024-50387

Severity
CRITICAL
CVSS
10.0
EPSS
0.1005
Risk score
43.52
CISA KEV
No
PoC
No
Published
2024-12-06
Modified
2024-12-06
First seen
2026-08-07
Aliases
EUVD-2024-45183, GHSA-5X22-49WV-3M34
Products
QNAP Systems Inc.:SMB Service 4.15.x <4.15.002, QNAP Systems Inc.:SMB Service h4.15.x <h4.15.002
Sources
euvd EUVD-2024-45183

Description

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already fixed the vulnerability in the following version: SMB Service 4.15.002 and later SMB Service h4.15.002 and later

References