安全ID : QSA-20-10
Multiple Vulnerabilities in Music Station
发布日期 : October 30, 2020
通用漏洞披露 : CVE-2018-19950 | CVE-2018-19951 | CVE-2018-19952
受影响产品: Music Station
严重程度
Important
状态
已解决
Summary
Three vulnerabilities have been reported to affect earlier versions of Music Station.
- CVE-2018-19950: If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.
- CVE-2018-19951: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
- CVE-2018-19952: If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information.
We have already fixed these issues in the following Music Station:
- QTS 4.3.3: Music Station 5.1.13 and later
- QTS 4.3.4: Music Station 5.1.13 and later
- QTS 4.3.6: Music Station 5.2.9 and later
- QTS 4.4.3: Music Station 5.3.11 and later
Recommendation
To fix the vulnerabilities, we recommend updating Music Station to the latest version.
Updating Music Station
- Log on to QTS as administrator.
- Open the App Center and then click
.
A search box appears.
- Type “Music Station” and then press ENTER.
Music Station appears in the search results.
- Click Update.
A confirmation message appears.
Note: The Update button is not available if your Music Station is already up to date.
- Click OK.
The application is updated.
致谢: Independent Security Evaluators
修订历史: V1.0 (October 30, 2020) - Published