A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network.
We have already fixed the vulnerability in the following version:
Photo Station 6.4.2 ( 2023/12/15 ) and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-13 |
|
History
Mon, 22 Sep 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap photo Station |
|
| CPEs | cpe:2.3:a:qnap:photo_station:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap photo Station |
Status: PUBLISHED
Assigner: qnap
Published: 2024-03-08T16:15:23.594Z
Updated: 2024-08-02T21:01:22.965Z
Reserved: 2023-11-03T09:47:36.054Z
Link: CVE-2023-47221
Updated: 2024-05-23T19:01:16.716Z
Status : Analyzed
Published: 2024-03-08T17:15:22.350
Modified: 2025-09-20T03:34:52.793
Link: CVE-2023-47221
No data.