Medium severity6.3NVD Advisory· Published Sep 6, 2024· Updated Jun 17, 2026
CVE-2024-27122
CVE-2024-27122
Description
A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network.
We have already fixed the vulnerability in the following versions: Notes Station 3 3.9.6 and later
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- QNAP Systems Inc./Notes Station 3v5Range: 3.9.x
cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:qnap:notes_station_3:*:*:*:*:*:*:*:*range: >=3.9.0,<3.9.6
- (no CPE)range: >=3.9.6
Patches
Vulnerability mechanics
References
1- www.qnap.com/en/security-advisory/qsa-24-21nvdVendor Advisory
News mentions
0No linked articles in our index yet.