CVE-2015-9102Cross-site Scripting in Synology Photo Station

Severity
5.4MEDIUMNVD
EPSS
0.3%
top 44.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 13

Description

Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos, (3) description of photos, or (4) tag of the photos.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5synology/photo_station6.0, 6.3+1

🔴Vulnerability Details

2
GHSA
GHSA-qj43-2xgx-mhc3: Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 62022-05-13
CVEList
CVE-2015-9102: Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 62017-06-30
CVE-2015-9102 — Cross-site Scripting in Synology | cvebase