Security ID : QSA-20-10

Multiple Vulnerabilities in Music Station


  • Release date : October 30, 2020

  • CVE identifier : CVE-2018-19950 | CVE-2018-19951 | CVE-2018-19952

  • Affected products: Music Station

Severity

Important

Status

Resolved


Summary

Three vulnerabilities have been reported to affect earlier versions of Music Station.

  • CVE-2018-19950: If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands.
  • CVE-2018-19951: If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code.
  • CVE-2018-19952: If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information.

We have already fixed these issues in the following Music Station:

  • QTS 4.3.3: Music Station 5.1.13 and later
  • QTS 4.3.4: Music Station 5.1.13 and later
  • QTS 4.3.6: Music Station 5.2.9 and later
  • QTS 4.4.3: Music Station 5.3.11 and later

Recommendation

To fix the vulnerabilities, we recommend updating Music Station to the latest version.

Updating Music Station

  1. Log on to QTS as administrator.
  2. Open the App Center and then click .

    A search box appears.

  3. Type “Music Station” and then press ENTER.

    Music Station appears in the search results.

  4. Click Update.
    A confirmation message appears.

    Note: The Update button is not available if your Music Station is already up to date.

  5. Click OK.

    The application is updated.

Acknowledgements: Independent Security Evaluators

Revision History: V1.0 (October 30, 2020) - Published

Choose specification

      Show more Less

      Choose Your Country or Region

      open menu
      back to top