PT-2017-7552 · Synology · Synology Video Station
Published
2017-06-30
·
Updated
2019-10-09
·
CVE-2015-9105
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Synology Video Station versions 1.2 before 1.2-0455
Synology Video Station versions 1.5 before 1.5-0772
Synology Video Station versions 1.6 before 1.6-0847
Description
The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the
file name or collection name of videos.Recommendations
For Synology Video Station versions 1.2 before 1.2-0455, update to version 1.2-0455 or later.
For Synology Video Station versions 1.5 before 1.5-0772, update to version 1.5-0772 or later.
For Synology Video Station versions 1.6 before 1.6-0847, update to version 1.6-0847 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synology Video Station