CVE-2015-9103: XSS
Published Jun 30, 2017
·Updated
Multiple cross-site scripting (XSS) vulnerabilities in Synology Note Station 1.1-0212 and earlier allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) note title or (2) file name of attachments.
Affected Software
1 affected component
Synology Note Station<=1.1-0212
Event History
Jun 30, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-9103?
CVE-2015-9103 is classified as a medium severity vulnerability due to its potential impact on web application security.
2
How do I fix CVE-2015-9103?
To fix CVE-2015-9103, upgrade Synology Note Station to version 1.1-0214 or later.
3
Which versions of Synology Note Station are affected by CVE-2015-9103?
CVE-2015-9103 affects Synology Note Station versions 1.1-0212 and earlier.
4
What type of vulnerabilities does CVE-2015-9103 include?
CVE-2015-9103 includes multiple cross-site scripting (XSS) vulnerabilities.
5
Who can exploit CVE-2015-9103?
CVE-2015-9103 can be exploited by remote authenticated attackers.