First published: Thu Aug 24 2017(Updated: )
Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.
Credit: security@synology.com
Affected Software | Affected Version | How to fix |
---|---|---|
Synology Photo Station | <=6.6.3-3347 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9555 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To fix CVE-2017-9555, update Synology Photo Station to version 6.7.0-3414 or later.
CVE-2017-9555 affects Synology Photo Station versions prior to 6.7.0-3414.
CVE-2017-9555 allows remote attackers to inject arbitrary web scripts or HTML through the image parameter.
Yes, CVE-2017-9555 has been patched in Synology Photo Station version 6.7.0-3414.