PT-2017-7552 · Synology · Synology Video Station
Publicado
2017-06-30
·
Atualizado
2019-10-09
·
CVE-2015-9105
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Synology Video Station versions 1.2 before 1.2-0455
Synology Video Station versions 1.5 before 1.5-0772
Synology Video Station versions 1.6 before 1.6-0847
Description
The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the
file name or collection name of videos.Recommendations
For Synology Video Station versions 1.2 before 1.2-0455, update to version 1.2-0455 or later.
For Synology Video Station versions 1.5 before 1.5-0772, update to version 1.5-0772 or later.
For Synology Video Station versions 1.6 before 1.6-0847, update to version 1.6-0847 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Synology Video Station