CVE-2017-15890: XSS
Published Dec 15, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.
Affected Software
1 affected component
Synology MailPlus Server<1.4.0-0415
Event History
Dec 15, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-15890?
CVE-2017-15890 is classified as a moderate severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-15890?
To fix CVE-2017-15890, upgrade Synology MailPlus Server to version 1.4.0-0415 or later.
3
What versions of Synology MailPlus Server are affected by CVE-2017-15890?
CVE-2017-15890 affects all versions of Synology MailPlus Server prior to 1.4.0-0415.
4
Can CVE-2017-15890 be exploited by remote users?
Yes, CVE-2017-15890 can be exploited by remote authenticated users to inject arbitrary web script or HTML.
5
What is the nature of the vulnerability in CVE-2017-15890?
The nature of CVE-2017-15890 is a cross-site scripting (XSS) vulnerability specifically affecting the NAME parameter.