PT-2018-12789 · Samsung · Samsung Syncthru Web Service
Published
2018-08-03
·
Updated
2018-09-27
·
CVE-2018-14904
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Samsung Syncthru Web Service version V4.05.61
Description
The issue concerns multiple unauthenticated XSS attacks. These attacks can be executed on several parameters, such as
ruiFw pid.Recommendations
For Samsung Syncthru Web Service version V4.05.61, consider restricting access to the vulnerable parameters until a patch is available. As a temporary workaround, avoid using the parameter
ruiFw pid in the affected API endpoints.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Samsung Syncthru Web Service