If exploited, this absolute path traversal vulnerability could allow attackers to traverse files in File Station. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.qnap.com/zh-tw/security-advisory/qsa-20-17 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: qnap
Published: 2020-12-24T01:39:28.422487Z
Updated: 2024-09-17T00:25:31.081Z
Reserved: 2019-12-09T00:00:00
Link: CVE-2020-2504
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-24T02:15:12.657
Modified: 2024-11-21T05:25:22.290
Link: CVE-2020-2504
Redhat
No data.