CVE-2018-8911: XSS
Published May 9, 2018
·Updated
Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Note Station before 2.5.1-0844 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.
Affected Software
1 affected component
Synology Note Station<2.5.1-0844
Event History
May 9, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2018-8911.
2
What is the severity of CVE-2018-8911?
The severity of CVE-2018-8911 is medium with a score of 5.4.
3
Which software version is affected by CVE-2018-8911?
The software version affected by CVE-2018-8911 is Synology Note Station before 2.5.1-0844.
4
How can remote authenticated users exploit CVE-2018-8911?
Remote authenticated users can exploit CVE-2018-8911 by injecting arbitrary web script or HTML via malicious attachments in Synology Note Station before 2.5.1-0844.
5
Is there any fix available for CVE-2018-8911?
Yes, a fix is available for CVE-2018-8911. It is recommended to update Synology Note Station to version 2.5.1-0844.