CVE-2015-9105: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collection name of videos.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-9105?
CVE-2015-9105 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-9105?
To fix CVE-2015-9105, upgrade to Synology Video Station version 1.2-0455, 1.5-0772, or 1.6-0847 or later.
Who is affected by CVE-2015-9105?
CVE-2015-9105 affects users of Synology Video Station versions before 1.2-0455, 1.5-0772, and 1.6-0847.
What type of vulnerabilities does CVE-2015-9105 include?
CVE-2015-9105 includes multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2015-9105 be exploited remotely?
Yes, CVE-2015-9105 can be exploited by remote authenticated attackers.