First published: Wed Dec 27 2017(Updated: )
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology MailPlus Server | <1.4.0-0415 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16768 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2017-16768, update Synology MailPlus Server to version 1.4.0-0415 or later.
CVE-2017-16768 affects remote authenticated users of Synology MailPlus Server versions prior to 1.4.0-0415.
CVE-2017-16768 is a cross-site scripting (XSS) vulnerability.
CVE-2017-16768 allows remote authenticated users to inject arbitrary HTML, which can result in phishing and session hijacking.