An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following versions: QuMagie 2.7.0 and later
An attacker can remotely, without needing to have an account, submit a specially crafted query containing malicious SQL code. The QuMagie application does not properly validate input data, which allows injection and execution of unauthorized commands on the database server side. The attack vector does not require user interaction, however certain special conditions may be required for successful exploitation (AT:P).
An attacker can execute unauthorized code or commands on the vulnerable system, potentially leading to application takeover, data disclosure or modification, and violation of system integrity and availability as well as related infrastructure.
QuMagie should be updated to version 2.7.0 or newer. Detailed information and patches are available in the official QNAP security bulletin: https://www.qnap.com/en/security-advisory/qsa-25-33
QNAP QuMagie in versions prior to 2.7.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XQnap Qumagie
APPQnap2.6.0 – 2.7.0 (excl.)
Related vulnerabilities
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The rem...
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...
A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can th...
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability cou...