CVE-2017-16771: XSS
Published Mar 22, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
Affected Software
2 affected components
Synology Photo Station>=6.8<6.8.3-3463
Synology Photo Station>=6.3<6.3-2971
Event History
Mar 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this cross-site scripting vulnerability?
The vulnerability ID is CVE-2017-16771.
2
What is the affected software?
The affected software is Synology Photo Station before 6.8.3-3463 and before 6.3-2971.
3
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by injecting arbitrary web script or HTML via the username parameter.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is medium with a CVSS score of 6.1.
5
How can I fix this vulnerability?
To fix this vulnerability, update Synology Photo Station to version 6.8.3-3463 or 6.3-2971.