CVE-2017-15892: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15892?
CVE-2017-15892 is considered a medium severity vulnerability due to its potential for exploitation via cross-site scripting.
How do I fix CVE-2017-15892?
To fix CVE-2017-15892, update Synology Chat to version 2.0.0-1124 or later.
What types of users are affected by CVE-2017-15892?
CVE-2017-15892 affects remote authenticated users who have access to the Slash Command Creator feature in Synology Chat.
What attack vectors are associated with CVE-2017-15892?
CVE-2017-15892 allows attackers to inject arbitrary web scripts or HTML through the COMMAND, COMMANDS INSTRUCTION, or DESCRIPTION parameters.
Are there any common exploitation techniques for CVE-2017-15892?
Common exploitation techniques for CVE-2017-15892 involve crafting malicious commands that leverage the XSS vulnerabilities to execute unexpected scripts.