Medium severity6.1NVD Advisory· Published Dec 10, 2020· Updated Jun 17, 2026
CVE-2020-2494
CVE-2020-2494
Description
This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:music_station:*:*:*:*:*:*:*:*range: <5.3.13
- (no CPE)range: QANP fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12 and later
- QNAP Systems Inc./Music Stationv5Range: < 5.3.13
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-20-13nvdVendor Advisory
News mentions
0No linked articles in our index yet.