Headline
CVE-2018-19950: Multiple Vulnerabilities in Music Station - Security Advisory
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.
<< Back to Security Advisory List
- Release date: October 30, 2020
- Security ID: QSA-20-10
- Severity: High
- CVE identifier: CVE-2018-19950 | CVE-2018-19951 | CVE-2018-19952
- Affected products: Music Station
- Status: Resolved
Summary
Three vulnerabilities have been reported to affect earlier versions of Music Station.
- CVE-2018-19950: If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.
- CVE-2018-19951: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
- CVE-2018-19952: If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information.
We have already fixed these issues in the following Music Station:
- QTS 4.3.3: Music Station 5.1.13 and later
- QTS 4.3.4: Music Station 5.1.13 and later
- QTS 4.3.6: Music Station 5.2.9 and later
- QTS 4.4.3: Music Station 5.3.11 and later
Recommendation
To fix the vulnerabilities, we recommend updating Music Station to the latest version.
Updating Music Station
Log on to QTS as administrator.
Open the App Center and then click .
A search box appears.
Type “Music Station” and then press ENTER.
Music Station appears in the search results.
Click Update.
A confirmation message appears.Note: The Update button is not available if your Music Station is already up to date.
Click OK.
The application is updated.
Acknowledgements: Independent Security Evaluators
Revision History: V1.0 (October 30, 2020) - Published