A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following version:
Photo Station 6.4.2 ( 2023/12/15 ) and later
We have already fixed the vulnerability in the following version:
Photo Station 6.4.2 ( 2023/12/15 ) and later
Metrics
Affected Vendors & Products
Fixes
Solution
We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.qnap.com/en/security-advisory/qsa-24-13 |
![]() ![]() |
History
Mon, 22 Sep 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Qnap
Qnap photo Station |
|
CPEs | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | |
Vendors & Products |
Qnap
Qnap photo Station |

Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2024-08-02T21:01:22.965Z
Reserved: 2023-11-03T09:47:36.054Z
Link: CVE-2023-47221

Updated: 2024-05-23T19:01:16.716Z

Status : Analyzed
Published: 2024-03-08T17:15:22.350
Modified: 2025-09-20T03:34:52.793
Link: CVE-2023-47221

No data.

No data.