CVE-2015-9104: XSS
Cross-site scripting (XSS) vulnerabilities in Synology Audio Station 5.1 before 5.1-2550 and 5.4 before 5.4-2857 allows remote authenticated attackers to inject arbitrary web script or HTML via the album title.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9104?
CVE-2015-9104 is classified as a medium severity vulnerability due to its potential impact on the security of the affected systems.
How do I fix CVE-2015-9104?
To mitigate CVE-2015-9104, update Synology Audio Station to version 5.1-2550 or 5.4-2857 or later.
What systems are affected by CVE-2015-9104?
CVE-2015-9104 affects Synology Audio Station versions 5.1-2541 through 5.1-2549 and 5.4-2852 through 5.4-2855.
What type of vulnerability is CVE-2015-9104?
CVE-2015-9104 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Who can exploit CVE-2015-9104?
CVE-2015-9104 can be exploited by remote authenticated attackers who have access to the audio station.