CVE-2017-16774: XSS
Published Apr 1, 2019
·Updated
Cross-site scripting (XSS) vulnerability in SYNO.Core.PersonalNotification.Event in Synology DiskStation Manager (DSM) before 6.1.4-15217-3 allows remote authenticated users to inject arbitrary web script or HTML via the package parameter.
Affected Software
2 affected components
Synology Diskstation Manager>=5.2<6.1.4-15217-3
Synology Diskstation Manager>=5.2<6.1.4-15217-3
Event History
Apr 1, 2019
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-16774?
CVE-2017-16774 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-16774?
To fix CVE-2017-16774, update Synology DiskStation Manager to version 6.1.4-15217-3 or later.
3
Who is affected by CVE-2017-16774?
CVE-2017-16774 affects remote authenticated users of Synology DiskStation Manager prior to version 6.1.4-15217-3.
4
What type of vulnerability is CVE-2017-16774?
CVE-2017-16774 is a cross-site scripting (XSS) vulnerability allowing injection of arbitrary web scripts or HTML.
5
Can CVE-2017-16774 be exploited remotely?
Yes, CVE-2017-16774 can be exploited remotely by authenticated users to execute malicious scripts.