CVE-2017-9555: XSS
Published Aug 24, 2017
·Updated
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
Affected Software
1 affected component
Synology Photo Station<=6.6.3-3347
Event History
Aug 24, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9555?
CVE-2017-9555 is classified as a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-9555?
To fix CVE-2017-9555, update Synology Photo Station to version 6.7.0-3414 or later.
3
What systems are affected by CVE-2017-9555?
CVE-2017-9555 affects Synology Photo Station versions prior to 6.7.0-3414.
4
What type of attack is possible with CVE-2017-9555?
CVE-2017-9555 allows remote attackers to inject arbitrary web scripts or HTML through the image parameter.
5
Has CVE-2017-9555 been patched?
Yes, CVE-2017-9555 has been patched in Synology Photo Station version 6.7.0-3414.